I12 Digital Forensics Basics Module Test
Demonstrate your understanding of fictional authorization, collection planning, evidence integrity, hashes, chain of custody, artifact analysis, volatile evidence, network and cloud correlation, timeline reasoning, findings, reporting, privacy, and portfolio safety.
Readiness Check
Module Test Readiness
0/5 ready
Assessment Rules
Complete All 25 Questions
Answer first
Select the strongest answer before opening the explanation.
Target score
Score at least 20 out of 25 before marking Module I12 complete.
Use bounded reasoning
Prefer answers that preserve authorization, evidence limits, alternatives, confidence, privacy, and source health.
Review missed concepts
Return to the matching lesson and revise the related fictional portfolio artifact after every missed question.
Check Your Understanding
I12 Module Test: Digital Forensics Basics
Choose your answers first. Explanations appear only after submission.
1. What should happen before a fictional digital-forensics review begins?
2. Which fictional case question is the most neutral and testable?
3. What does data minimization require in a fictional forensic case?
4. What should happen when a supplied fictional record references an out-of-scope folder?
5. Which factors should shape fictional evidence-collection priority?
6. Why should an approved supplied export sometimes be used instead of contacting a live source?
7. What is the correct relationship between fictional original evidence and a working copy?
8. What can a matching fictional content hash most directly support?
9. What should happen after a fictional working copy fails integrity verification?
10. Which information belongs in a fictional chain-of-custody transfer record?
11. Which statement is a direct fictional observation?
12. Why should a fictional filename extension not be treated as proof of file format?
13. What should be checked before comparing fictional timestamps from different sources?
14. What can a fictional recent-item artifact support?
15. Why is fictional volatile evidence time-sensitive?
16. What can a fictional parent-child process relationship support?
17. What can an open fictional file handle support?
18. What can a fictional network-flow record most directly support?
19. What is independent corroboration?
20. How should a fictional application record with separate event and receipt times be placed in a timeline?
21. When can fictional negative evidence be useful?
22. Why should earlier fictional timeline versions be preserved?
23. What is the strongest structure for a fictional forensic finding?
24. How should the same fictional finding be communicated to technical and leadership audiences?
25. Which final conclusion is best supported by the fictional Northbridge evidence?
Score Guide
Interpret Your Module-Test Result
23–25
Excellent mastery. Your evidence reasoning, limits, and communication are consistently professional.
20–22
Module standard achieved. Review missed questions and improve the matching portfolio sections.
16–19
Developing mastery. Revisit the weakest lessons and retake the test after revising your case package.
0–15
Rebuild the foundations. Review I12.1 through I12.8 in order before attempting the module test again.
Mastery Review
Connect Missed Questions to the Correct Lesson
I12.1
Authorization, ethics, privacy, scope, minimization, and stop conditions
I12.2
Evidence sources, collection priority, volatility, source health, and alternate evidence
I12.3
Integrity, hashes, originals, working copies, chain of custody, and lineage
I12.4
Files, metadata, timestamps, hashes, artifacts, observations, and findings
I12.5
Processes, sessions, parent-child relationships, handles, connections, and snapshot limits
I12.6
Network and cloud evidence, timestamp normalization, source independence, and versioned timelines
I12.7
Findings, confidence, limitations, exhibits, audience communication, and corrections
I12.8
Integrated case reasoning, final conclusions, reporting package, and portfolio safety
Defender Habits
Module I12 Mastery Checklist
Portfolio Prompt
Final Module Portfolio Check
Review your fictional Northbridge Digital Forensics Basics Case Package. Confirm that it includes an authorization brief, collection plan, evidence register, chain of custody, integrity records, artifact worksheet, process and session map, source-health register, timeline versions 1 and 2, findings matrix, technical report, executive summary, privacy statement, support note, technical-owner brief, evidence exhibits, reviewer checklist, correction record, communication log, lessons learned, closure criteria, and portfolio-safety statement.
Key Takeaways
What You Should Remember
Module Navigation