FIA Past Paper 10By haseeb lali / July 6, 2026 FIA Past Paper 10 1 / 100 A train 480 m long crosses a pole in 24 seconds. Speed is: 60 km/h 66 km/h 72 km/h 80 km/h 2 / 100 A train 360 m long crosses a 540 m platform in 45 seconds. Speed is: 60 km/h 66 km/h 72 km/h 78 km/h 3 / 100 A boat speed in still water is 20 km/h and stream speed is 5 km/h. Time to travel 75 km downstream and 45 km upstream is: 5 hours 6 hours 7 hours 8 hours 4 / 100 Find the next number: 13, 28, 59, 122, 249, ___ 502 504 506 508 5 / 100 Find the next number: 8, 19, 41, 85, 173, ___ 347 349 357 370 6 / 100 Find the next number: 5, 16, 49, 148, 445, ___ 1334 1336 1338 1339 7 / 100 Find the next letter: E, J, P, W, E, ___ L M A S 8 / 100 If x + y = 34 and xy = 273, then x² + y² =: 600 610 620 630 9 / 100 If x - y = 15 and xy = 286, then x² + y² =: 777 787 797 779 10 / 100 Ratio of two numbers is 15:23 and their sum is 456. Larger number is: 252 264 276 294 11 / 100 A number is increased by 125% and then decreased by 55.56%. Net change is approximately: 0% 5% 8% 9% 12 / 100 Average of 30 numbers is 54. If one number 112 is removed, new average is: 50 51 52 53 13 / 100 Probability of getting no tail when four coins are tossed is: 1/4 1/8 1/16 1/32 14 / 100 LCM of 54, 72, and 90 is: 360 660 960 1080 15 / 100 HCF of 198, 330, and 462 is: 33 66 99 105 16 / 100 A dishonest shopkeeper uses 650 g instead of 1 kg but sells at cost price. His gain is approximately: 35.85% 42.86% 53.85% 65.00% 17 / 100 Which is most important when collecting electronic evidence? Speed only Preserving integrity and authenticity Changing file names for clarity Copying only visible files 18 / 100 In digital forensics, a write blocker is used to: Increase storage speed Prevent alteration of original evidence Delete malware Encrypt files 19 / 100 The main purpose of calculating a hash value is to: Verify data integrity Compress the file Increase file size Hide the file 20 / 100 Which of the following is an example of volatile evidence? Printed document External hard drive DVD RAM data 21 / 100 Chain of custody means: List of police stations Court punishment record Documented record of evidence handling List of witnesses only 22 / 100 Which action should be avoided while collecting digital evidence? Photographing the setup Documenting device condition Directly opening files on the original device Using forensic tools 23 / 100 A forensic image is: A photograph of the suspect A complete bit-by-bit copy of storage media A screenshot only A compressed folder 24 / 100 Metadata refers to: Data about data Deleted data only Encrypted data only Network cables 25 / 100 Which hash algorithm is commonly used to verify file integrity? HTML SHA-256 HTTP FTP 26 / 100 The first step after seizing a mobile phone should usually be to: Open all apps Preserve it from remote access and alteration Delete suspicious messages Change the password 27 / 100 Faraday bags are used to: Charge mobile phones Increase internet speed Block wireless signals Recover deleted files 28 / 100 Which evidence is most likely to be lost after shutting down a computer? RAM contents Hard disk files Printed files USB casing 29 / 100 The best practice before analyzing a hard drive is to: Work on the original drive Format the drive Create and verify a forensic copy Rename all folders 30 / 100 A hash mismatch between original evidence and forensic copy means: The copy is verified The evidence may have been altered or copied incorrectly The evidence is automatically fake The device is encrypted 31 / 100 Digital evidence should be stored in a way that ensures: Easy public access Security, integrity, and restricted access Editing convenience Fast deletion 32 / 100 Which of the following may contain browser history? Web browser cache Keyboard cable Monitor stand Printer tray only 33 / 100 Deleted files can sometimes be recovered because: They never leave the computer They become printed automatically Their data may remain until overwritten They are stored in RAM forever 34 / 100 In cyber investigations, log files are useful because they can show: User activity and system events Only file colors Monitor brightness Keyboard brand 35 / 100 Which is the safest method for preserving digital evidence? Make changes to organize files Share evidence through social media Copy selected files only Use proper forensic procedures and documentation 36 / 100 Evidence authenticity means: Evidence is large in size Evidence is genuine and what it claims to be Evidence is stored online Evidence is translated 37 / 100 Which of the following is most important in a forensic report? Personal opinion only Clear method, findings, and supporting details Long unrelated details Accusations without evidence 38 / 100 A screenshot alone is generally weaker than a forensic capture because: It is always illegal It cannot show images It may not preserve full metadata and integrity It takes too much space 39 / 100 Which device can store digital evidence? Mobile phone USB drive Cloud account All of the above 40 / 100 The purpose of documenting the date, time, and person handling evidence is to: Increase paperwork only Maintain chain of custody Delay investigation Replace court record 41 / 100 Which of the following is poor evidence handling? Using tamper-evident packaging Labeling evidence properly Leaving evidence unsecured Maintaining custody record 42 / 100 In digital forensics, “integrity” means: The evidence has not been improperly changed The evidence is colorful The device is expensive The file is password-protected only 43 / 100 Which evidence source is most useful for proving login activity? System logs Desktop wallpaper Keyboard design Screen size 44 / 100 Which of the following should be collected first when live data is needed? Volatile data Printed manuals Empty folders Old CDs 45 / 100 A digital forensic examiner should be: Neutral and methodical Biased toward the complainant Biased toward the accused Interested only in confession 46 / 100 Which is an example of electronic evidence? Email record Chat message CCTV footage All of the above 47 / 100 Why should original evidence not be modified? It may damage evidentiary value It improves the case It reduces file size It makes evidence faster 48 / 100 A forensic timeline helps investigators understand: Sequence of digital events Device color Screen resolution Battery brand 49 / 100 Which information can email headers provide? Routing and technical delivery details Only font size Only message color Only attachment name 50 / 100 Which of the following is a risk in cloud evidence collection? Jurisdiction and access control issues Lack of internet colors Keyboard failure only Printer speed 51 / 100 Which is the best description of admissible evidence? Evidence accepted by court according to law Evidence posted online Evidence collected without record Evidence copied randomly 52 / 100 What should investigators do before disconnecting a running computer, when possible? Consider whether volatile evidence must be captured Delete temporary files Install games Change user settings 53 / 100 Which of the following can affect the credibility of electronic evidence? Proper documentation Broken chain of custody Verified hash value Secure storage 54 / 100 A forensic copy should be analyzed instead of the original because: It destroys the original It removes metadata It protects the original evidence It changes timestamps 55 / 100 Which is most likely to prove that a file was changed? Different hash value Same file name Same folder icon Same screen color 56 / 100 Evidence stored on a suspect’s phone may include: Call logs Messages Location data All of the above 57 / 100 Which principle is central to digital evidence handling? Minimize alteration of original evidence Edit evidence for readability Share evidence with friends Delete irrelevant folders immediately 58 / 100 Which of the following is a cybercrime-related evidence source? IP logs Email records Server logs All of the above 59 / 100 Which action helps prove that evidence was not tampered with? Hash verification Renaming files Opening files repeatedly Copying only screenshots 60 / 100 If a seized laptop is encrypted, investigators should: Follow lawful forensic procedure Randomly delete files Format the hard drive Ignore documentation 61 / 100 Digital evidence is fragile because: It can be easily altered, deleted, or overwritten It is always visible It cannot be copied It never changes 62 / 100 Which of the following is best for storing seized digital evidence? Secure evidence room with access control Personal laptop Public computer Social media folder 63 / 100 What does “read-only access” help prevent? Unauthorized modification of evidence Evidence documentation File identification Court review 64 / 100 Which of the following is most important in presenting electronic evidence in court? File size only Device price Reliability, relevance, and integrity Number of folders 65 / 100 What should be recorded when collecting electronic evidence? Device details, condition, time, place, and handler Only investigator’s name Only suspect’s name Only file names 66 / 100 The strongest approach in digital evidence collection is to: Quickly copy random files Depend only on memory Follow a documented, repeatable, and legally valid process Allow anyone to inspect the device 67 / 100 The main purpose of imaging a hard drive is to: Make a casual backup Create an exact forensic copy Delete hidden files Increase disk speed 68 / 100 Which of the following should be avoided during evidence collection? Labeling evidence Documenting the process Changing system settings Using secure storage 69 / 100 A forensic hash value helps prove that: The file is large The file has not changed The file is compressed The file is hidden 70 / 100 Which type of evidence can be found in browser cookies? Web activity information Printer ink level Keyboard model Screen brightness 71 / 100 When collecting evidence from a live computer, investigators should first consider: Volatile data Wallpaper Monitor size Keyboard color 72 / 100 A proper evidence label should include: Device details and collection information Only file size Only brand name Only password 73 / 100 Which of the following is an example of network evidence? Firewall logs IP logs Router logs All of the above 74 / 100 Digital evidence must be handled carefully because it is: Difficult to print Easily altered or deleted Always encrypted Always visible 75 / 100 A forensic examiner should work mainly on: The original device A verified forensic copy A random screenshot A renamed folder 76 / 100 The purpose of a seizure memo is to: Record details of seized items Delete files from devices Install software Change passwords 77 / 100 Which action can damage the integrity of electronic evidence? Using a write blocker Maintaining chain of custody Opening files directly on the original device Creating a forensic image 78 / 100 In digital forensics, deleted files may be found in: Unallocated space Monitor screen Keyboard memory only Printer cable 79 / 100 The term “bit-by-bit copy” means: A partial copy of selected files A complete copy of all data sectors A screenshot of folders A printed file list 80 / 100 Which document proves who handled evidence and when? Chain of custody record Attendance sheet Salary slip Complaint diary only 81 / 100 Which is the best method to protect mobile evidence from remote wiping? Keep it connected to Wi-Fi Use airplane mode or Faraday protection according to procedure Open all apps immediately Restart it repeatedly 82 / 100 Which of the following may contain location evidence? Mobile GPS data Photo metadata App records All of the above 83 / 100 Which term means proving that evidence is genuine? Authentication Deletion Compression Formatting 84 / 100 A forensic report should be: Clear, objective, and based on findings Emotional and accusatory Written without method Based only on suspicion 85 / 100 Which of the following is a common source of digital evidence in financial cybercrime? Transaction logs Email records Banking app data All of the above 86 / 100 Why are timestamps important in digital evidence? They show timing of events They increase file size They remove passwords They encrypt data 87 / 100 Which is an example of poor digital evidence practice? Using forensic software Recording hash values Copying evidence without documentation Maintaining custody record 88 / 100 Which evidence can help identify unauthorized access? Login logs Access logs Failed login attempts All of the above 89 / 100 Digital evidence collected without proper procedure may become: Immediately pull the plug in every case Follow procedure based on circumstances and preserve volatile evidence if needed Delete running programs Change user account names 90 / 100 Which of the following can preserve evidence integrity? Write blocker Hashing Proper documentation All of the above 91 / 100 What is the purpose of access control in evidence storage? To limit evidence handling to authorized persons To allow public access To change file names To increase storage size 92 / 100 A forensic image differs from a normal copy because it: Captures only visible files Captures complete data, including hidden and deleted areas Deletes temporary files Changes file extensions 93 / 100 Which evidence may help prove communication between suspects? Chat logs Email records Call logs All of the above 94 / 100 The role of a digital forensic expert is to: Collect, preserve, analyze, and report evidence Decide punishment Act as judge Hide weak evidence 95 / 100 Which of the following may contain evidence of file transfer? USB connection logs Network logs Cloud sync logs All of the above 96 / 100 Which principle should guide electronic evidence collection? Evidence should remain unchanged as far as possible Evidence should be edited for clarity Evidence should be shared widely Evidence should be copied without record 97 / 100 Which is the best reason to photograph a digital crime scene? To decorate the case file To document original device setup and surroundings To replace forensic imaging To avoid written notes 98 / 100 Which of the following is not a good practice? Keeping evidence in sealed packaging Maintaining a custody log Allowing unauthorized access to evidence Recording collection details 99 / 100 In a cybercrime investigation, IP address logs may help identify: Network connection activity Keyboard language only Monitor brand Printer paper size 100 / 100 Which of the following can be considered electronic evidence? CCTV footage Email Mobile data All of the above Your score isThe average score is 17% 0% Restart quiz