Browse all practice questions for the Cybercrime Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Cybercrime Practice Test 2026 - Free Cybersecurity Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • What ensures consistent timestamps across logs in incident detection?
  • Which security technology works to scramble computer messages and/or data?
  • Which crime scene is the most complex to investigate?
  • Which federal agency houses CCIPS?
  • Which statement best reflects online privacy and harassment?
  • What term describes devices or software that act as a checkpoint between the network and individual users?
  • The National Cyber Response Coordination Group is composed of how many federal agencies that respond to cyber-attacks?
  • The largest and primary investigative arm of the U.S. Department of Homeland Security is which agency?
  • Which statement best captures the observed disparity between federal and local cyber cops?
  • Which OSI layer handles end-to-end communication and reliable data transfer between applications?
  • Which layer corresponds to 'policies' in the described layer scheme?
  • Which statement is MOST true about the globalization of hacking?
  • CCIP works in close collaboration with which entity in the prosecution of computer crimes?
  • Which statement best reflects the relationship between state laws and technology pace?
  • What is a cryptographic hash and why is it used in digital forensics?
  • Which list represents the five or six steps of an incident response lifecycle commonly referenced in frameworks?
  • The chief law enforcement officer of the federal government is the director of Homeland Security.
  • Which OSI layer provides logical addressing and path determination between networks?
  • What is the primary distinction between cybercrime and conventional crime?
  • Which of the following is a logging best practice for incident detection?
  • The most popular password generator is:
  • What is a botnet and how do attackers typically control infected machines?
  • A multi-scene crime involves multiple locations.
  • What is log correlation?
  • Which statement about the relationship between drug trafficking and cybercrime trait profiles is supported by the material?
  • The DHS subsumed the Federal Emergency Management Agency.
  • Which tool is designed primarily to log network traffic and examine it for known attack patterns?
  • Which of the following is NOT a method to secure wireless networks?
  • Which of the following is a characteristic of the black market?
  • Which of the following is an Indicator of Compromise (IOC)?
  • What is credential stuffing?
  • Which layer corresponds to 'application' in the described layer scheme?
  • What factors have limited the ability of local law enforcement to respond to the growing threat of computer crime?
  • Name a major challenge in cloud forensics.
  • The most pressing computer crimes enforced by local law enforcement agencies appear to be those related to which category?
  • Which statement about overall cybersecurity enforcement is most accurate?
  • The facets of the hacker culture are likely to:
  • Which statement best describes the role of 'Identify threats' in risk analysis?
  • Which entity is described as responsible for the storage of evidence until the time of trial?
  • Which of the following is a cybercrime reporting channel designed for nationwide coordination?
  • When collecting data during a live incident, which data type should be prioritized due to volatility?
  • NOT a characteristic of intruders during the first era of computer security?
  • Which statement describes a NOT common cybercrime reporting channel for individuals or organizations?
  • Explain the concept of social engineering in cybercrime and name two common techniques.
  • Which OSI layer handles data representation, encryption, and compression for communication between applications?
  • Which layer is described as 'Provides checkpoint, fall back, and encryption services (e.g., SSL)'?
  • Which of the following best describes data at rest versus data in transit and a typical protection for each?
  • A sector-by-sector copy preserves what aspect of data that a simple file copy might not?
  • What is a forensic image and why is it important to create a bit-for-bit copy?
  • Which OSI layer is primarily concerned with encoding and modulation of signals on the transmission medium?
  • Which of the following is not a division of the Bureau of Consumer Protection within the FTC?
  • Which trend is described as a significant threat to global networks due to hacking?
  • Who is the chief law enforcement officer of the U.S. federal government?
  • The claim that the NSA has provided code-breaking capabilities since the Civil War is historically accurate.
  • Name three common sources of digital evidence in a corporate investigation.
  • Virtual crimes against persons such as stalking and harassment are facilitated by:
  • Biometrics are commonly used as a form of which security function?
  • Which OSI layer is typically associated with MAC addressing and Ethernet frames?
  • How is a geographically compact crime scene under the administrative control of a single entity classified?
  • Which agency is the lead for monitoring and protecting all federal government computer networks from cyberterrorism?
  • Define zero trust security and its core principle.
  • The greatest number of Internet users are in which combination of regions?
  • Which of the following would NOT be considered one of the three commonly cited malware types in this material?
  • In the early era of computer security intruders, the majority of intruders came from which source?
  • Distinguish credential stuffing vs phishing.
  • According to the survey data, what percentage of local police agencies reported a measurable increase in reporting computer and electronic crimes?
  • Which statement describes a defense-in-depth approach?
  • Which of the following is NOT a form of telecommunications fraud?
  • Which federal agency houses the Customs Cyber Smuggling Center (3C)?
  • Regarding current organized crime groups, which statement is true?
  • Which artifact is most useful for establishing who accessed a system and when?
  • The CSSS arrests and prosecutes the sale and distribution of counterfeit pharmaceuticals and controlled substances over the Internet through which operation?
  • GDPR and HIPAA domains: what type of data does each primarily govern?
  • Which agency is associated with cryptology and signals intelligence in the U.S. government?
  • Which statement about sources of federal contact information for local investigators is accurate?
  • The IP address is associated with which layer of the OSI model?
  • The entity that provides victims of Internet fraud with a mechanism to report suspicious online activities is known as which?
  • IC3 is operated in partnership with which federal agency?
  • Which agency coordinates federal emergency management and is associated with the DHS?
  • Which of the following is a characteristic of the black market?
  • Which statement describes the size and impact of e-commerce on the economy?
  • Why is data minimization emphasized in GDPR during cybercrime investigations?
  • The most effective tool for dealing with Internet fraud is:
  • Which center is the primary channel for submitting Internet crime complaints to federal authorities?
  • What is the purpose of chain of custody in digital evidence handling?
  • Which statement is true about the trend in reported cyber crimes?
  • Which statement best describes the Postal Service's role in fighting computer-generated crimes since the creation of DHS?
  • Which OSI layer is described as providing a path for the transmission of bits over cables, fiber, and radio waves?
  • Which activity would be considered 'exceeding authorized access' under the CFAA?
  • Which layer's responsibilities include framing, error detection, and flow control in LAN technologies such as Ethernet?
  • In forensics, what is the purpose of image verification?
  • What is a hash collision and why does it matter in forensics?
  • The single greatest problem in computer security is:
  • In digital forensics, what is the primary reason to maintain a chain of custody?
  • The National Computer Security Survey found that ____% of the businesses sampled experience at least one cybercrime in 2005.
  • In a ransomware incident, what typically happens after encryption of files?
  • Active versus passive network defense techniques: which statement is accurate?
  • According to the data, what percentage of local police agencies experienced a measurable increase in reporting computer and electronic crimes?
  • Which statement is LEAST true about online harassment and privacy?
  • In what year was the FBI established?
  • Which of the following is NOT a form of telecommunications fraud?
  • Which address type is used to uniquely identify a device on the local network?
  • Which of the following best describes data in transit protection?
  • NOT be considered part of a formal risk analysis?
  • HIPAA primarily governs which type of data?
  • Which OSI layer is responsible for establishing, managing, and terminating connections between applications across a network?
  • Which statement accurately contrasts defense in depth with a single point of failure in security architecture?
  • Name two common legal concepts relevant to digital evidence admissibility.
  • Which of the following is a high-level method attackers use to exfiltrate data?
  • What is the evolution in IT technology often referred to as the next generation of firewall technology?
  • Which statement correctly describes training in computer crime for patrol personnel in local agencies?
  • Cyber-based attacks and high technology crimes are of low priority for the FBI.
  • Which OSI layer sits directly above the Physical layer and handles framing and MAC addressing in Ethernet networks?
  • Which of the following is not a role of the FBI in fighting computer crime?
  • DNS tunneling is used for what purpose in cybercrime?
  • What is "log retention policy" and its role in cybercrime investigations?
  • The disparity in equipment between federal and local cyber cops is most clearly seen in the inability of most local agencies to do what?
  • Differences between IP and MAC addresses?
  • Which OSI layer is responsible for assembling bits into frames, performing error detection, and handling flow control in Ethernet networks?
  • Local law enforcement agencies' most important critical need to improve cybercrime response is which of the following?
  • Which agency leads investigations into access device fraud?
  • Which of the following is another typical digital evidence artifact encountered in investigations?
  • Approximately ___% of the population is covered by NIBRS reporting.
  • Which layer is described as 'Standardizes data transmission formats (e.g., JPEG)'?
  • BYOD concerns include which of the following?
  • NOT a limitation in risk analysis for early computing?
  • The trio of regions with the largest Internet user base includes which regions?
  • Which term describes the disparity in equipment between federal and local cyber personnel?
  • Unless a computer system holds a particular interest, the most likely threat comes from:
  • Which layer is described as 'Allows multiple simultaneous operations across a single network connection (e.g., TCP)'?
  • Which of the following is the largest computer crime problem affecting local law enforcement with the largest number of victims?
  • What is the difference between a sector-by-sector copy and a file-level copy in forensics?
  • Which statement best distinguishes authentication from authorization?
  • Which factor is NOT listed as a limiting factor for local law enforcement in responding to computer crime?
  • Which basic step in risk analysis should be performed second?
  • Which offense is most likely to touch the largest number of community members in the near future?
  • Which layer is described as 'The human being using the computer and network'?
  • When storing computer evidence, which of the following should be recorded?
  • Which layer is described as 'Provides unique addressing for transmission across different networks (e.g., IP)'?
  • Which statement best describes local officers' capacity for computer crime investigations?
  • Which organization is described as the largest and primary investigative arm of the Department of Homeland Security?
  • Which option correctly pairs a malware type with its defining characteristic?
  • Name two core offenses defined by the CFAA in the United States.
  • Define volatile data and its relevance in live digital investigations.
  • Which statement about USPS involvement in interagency cybercrime work is most accurate?
  • Which of the following is not a critical infrastructure component?
  • The term describing the growing inability of federal law enforcement to collect evidence from electronic communications over the Web is called what?
  • Why is hash verification important after imaging a drive in forensics?
  • What is phishing and how does spear phishing differ from general phishing?
  • Which statement about the FBI's public sector partnerships is correct?
  • Bitcoins are not an anonymous form of electronic payment.
  • Which OSI layer is primarily responsible for end-to-end reliability and flow control between applications?
  • Which of the following is a widely used authentication technology?
  • Which statement best describes the FBI's public sector partnerships?
  • Which statement best describes the evidence of disparity between federal and local equipment?
  • A U.S. Department of Defense study on emerging threats to national security observed that the field of battle is increasingly moving toward:
  • This security technology can involve biometrics.
  • Define a digital footprint and its relevance to cybercrime investigations.
  • Which option illustrates a key capability local agencies lack when handling cyber evidence?
  • Explain the concept of "order of volatility" in data collection.
  • Ethernet operates at which OSI layer for its basic data handling features such as framing and error detection?
  • Which GDPR principle emphasizes collecting only data that is necessary for a stated purpose?
  • Script Kiddies best described as?
  • In cybercrime investigations, why is MLAT important?
  • Which layer corresponds to 'user' in the described layer scheme?
  • Which of the following is a typical digital evidence artifact encountered in investigations?
  • The most important critical need among local law enforcement agencies is which of the following?
  • Which basic step in risk analysis should be performed first?
  • Which layer corresponds to 'network' in the described layer scheme?
  • Which layer is described as 'Provides direct interaction with the user (e.g., Explorer, Firefox, Chrome)'?
  • Which federal agency is primarily responsible for protecting consumers against computer-generated commercial fraud?
  • Based on the material, which statement best captures the overall projected trend in cybercrime?
  • Which agency has primary jurisdiction in cases involving access device fraud?
  • The character of espionage is expected to broaden into which of the following arenas?
  • What is described as the most fundamental skill set of an electronic crimes investigator?
  • The profiles of individuals at the higher levels of drug trafficking and cybercrime share common personality traits.
  • What is a CSIRT and how does it differ from a CERT?
  • Which statement best describes the role of IP addresses?
  • Which statement about joint investigations involving the U.S. Postal Service is accurate?
  • In the OSI model, which layer is mainly concerned with the raw transmission of bits over a physical medium?
  • Threats to ______________ are threats that actually alter data.
  • What is the primary purpose of a risk assessment in cybersecurity?
  • Which technology allows a firewall to block traffic from a known bad location?
  • Name a standard forensic principle for ensuring evidence reliability.
  • Terrorist groups will likely use computers and networks for all of the following except:
  • The Bureau of Consumer Protection operates under which U.S. government agency?
  • Explain the concept of time stamping in digital investigations and its importance.
  • Which statement best characterizes the modern trend among organized crime groups with respect to technology?
  • Minimization means:
  • Which security property is encryption primarily intended to protect?
  • Threat intelligence plays what role in cybercrime prevention?
  • What is malware staging in cyberattacks?
  • What does MLAT stand for in cybercrime investigations?
  • Which category of threat is associated with unauthorized disclosure of information?
  • Which of the following is a form of new technology of user identification?
  • What is NOT a category of threats to information systems?
  • Which statement best describes the primary purpose of a log retention policy?
  • Which practice most directly supports evidence integrity in digital forensics?
  • Describe a basic ransomware lifecycle from initial access to recovery options.
  • What is "encryption at rest" and "encryption in transit," and why both matter?
  • Experts believe computer hackers in developing countries will be increasingly motivated by which of the following?
  • Which classic element of computer security is generally not required for an encryption scheme?
  • Which agency is known as the nation's preeminent cryptological organization?
  • A WAN that uses a common addressing and transfer protocol suite called Transfer Control Protocol/Internet Protocol is called a(n) ________.
  • Which federal agency collaborates with the Computer Incident Advisory Capability (CIAC)?
  • What is the data minimization principle in GDPR and why does it matter in cybercrime investigations?
  • What is the purpose of write-blockers in forensic collection?
  • IP addressing operates at which OSI layer?
  • Which term describes an evolution of firewall capabilities that inspects data packets at deeper levels?
  • If an investigator finds a computer that is turned off during a search with a warrant, what should be done?
  • Memory forensics focuses on analyzing volatile memory. Which artifacts can RAM reveal?
  • Which OSI layer handles frames rather than packets or segments?
  • BYOD stands for Bring Your Own Device. What cybersecurity concern does it raise?
  • Encryption is used to protect data by performing which action on the data?
  • CCIPS attorneys conduct hundreds of training seminars every year for other federal attorneys.
  • Which statement about the U.S. Department of Energy's focus is accurate?
  • Which statement reflects the capacity of local officers to handle computer crimes?
  • What is GDPR and one major principle it enforces?
  • The best source for technical information needed in a network investigation is:
  • Which term describes a private network that uses TCP/IP and is restricted to members of an organization?
  • Which statistic reflects cybercrime prevalence across businesses in 2005?
  • ___________________ are the most important security measure a company or individual can take.
  • Which layer is described as 'The rules, policies, and management controls that govern the actions of users'?
  • The facets of the hacker culture are likely to increase the odds that some groups will become organized criminal enterprises.
  • IC3 is operated in partnership with which federal agency?
  • Which statement best describes ransomware?
  • Which statement best differentiates incident response from disaster recovery in organizational cybersecurity planning?
  • What best defines data exfiltration?
  • After 'Assess and evaluate' which step is next?
  • Which social engineering technique involves creating a fabricated scenario to obtain information?
  • What portion of the population is not covered by NIBRS reporting, given that 29% are covered?
  • What is zero-day vulnerability?
  • CCIP collaborates with which department in the prosecution of computer crimes?
  • Which basic step in risk analysis should be performed last?
  • Which OSI layer would be most associated with routing packets through a network?
  • What is an Indicator of Compromise (IOC) and give two examples.
  • Which statement about MAC addresses is correct?
  • Which layer corresponds to 'presentation' in the described layer scheme?
  • According to surveys, what percentage of local law enforcement agencies do not have adequate capabilities to read encrypted evidence?
  • In the future, terrorists will likely use all of the following tactics, except:
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy