Network activity, Application usage, Logs and Keystroke monitoring are all sources of what?
A
DataCorrect Answer
B
Malware
C
Forensic dead-ends
D
Leaks
QUESTION 7 OF 41
What are the three (3) main hurdles that must be overcome when examining data? (Select 3)
FORENSIC DATA KNOWLEDGE CHECK
A
Dealing with a sea of data. A single hard drive will contains many thousands of files that are not relevant to our investigation.Correct Answer
B
Selecting the most effective tools to help with the searching and filtering of data.Correct Answer
C
Bypassing controls such as operating system and encryption passwords.Correct Answer
D
Not tripping malware booby traps that were setup to prevent examination of data.
QUESTION 8 OF 41
True of False. Only data files can be effectively analyzed during a forensic analysis.
A
True
B
FalseCorrect Answer
QUESTION 9 OF 41
Most data files are smaller than the number of blocks allocated to their storage by the file system, the unused spaces is known as what?
A
Block buffer space
B
Slack spaceCorrect Answer
C
Free space
D
Allocation overage space
QUESTION 10 OF 41
What does file metadata known as "MAC" data stand for in the context of a forensic analysis?
A
Machine Access Control
B
Metadata associated with i/OS files
C
Machine Allocated Content
D
Modification, Access and Creation timesCorrect Answer
QUESTION 11 OF 41
Open files are considered which data type?
A
Non-volatile
B
Dynamic
C
VolatileCorrect Answer
D
Static
QUESTION 12 OF 41
True or False. When collecting forensic data from a running system, you should always attempt to collect volatile data first.
A
TrueCorrect Answer
B
False
QUESTION 13 OF 41
Which operating system has a "Target Disk Mode" that allows a forensic investigator to easily make a copy of the target hard drive?
A
Mac OS XCorrect Answer
B
Microsoft Window
C
Linux
D
UNIX
QUESTION 14 OF 41
Which three (3) of the following are application components? (Select 3)
A
Supporting filesCorrect Answer
B
Operating system DLLs
C
Log filesCorrect Answer
D
Configuration settingsCorrect Answer
QUESTION 15 OF 41
Which of these applications would likely be of the most interest in a forensic analysis?
A
EmailCorrect Answer
B
OSI Application Layer protocols
C
Patch files
D
Operating system DLLs
QUESTION 16 OF 41
What useful foresnsic data can be extracted from the Application layer of the TCP/IP protocol stack?
A
HTTP addressesCorrect Answer
B
TCP addresses
C
UDP addresses
D
ICMP addresses
QUESTION 17 OF 41
Which device would you inspect if you were looking for failed attempts to penetrate your company)s network?
DIGITAL FORENSICS ASSESSMENT
A
FirewallCorrect Answer
B
Intrusion detection system
C
Packet sniffer
D
Remote access server
QUESTION 18 OF 41
Digital forensics is commonly applied to which of the following activities?
A
Criminal investigation
B
Incident handling
C
Data recovery
D
All of the aboveCorrect Answer
QUESTION 19 OF 41
NIST includes which three (3) as steps in collecting data? (Select 3)
A
Develop a plan to aquire the dataCorrect Answer
B
Verify the integrity of the dataCorrect Answer
C
Acquire the data
D
Normalize the data
QUESTION 20 OF 41
What is the primary purpose of maintaining a chain of custody?
A
So a person in possession of evidence will know who they are allowed to give it to next
B
To keep valuable hardware securely locked to tables or floors.
C
To allow for accurate client billing
D
To avoid allegations of mishandling or tampering of evidence.Correct Answer
QUESTION 21 OF 41
True or False. Digital forensics had been used to solve a number of high-profile violent crimes.
A
TrueCorrect Answer
B
False
QUESTION 22 OF 41
True or False. Digital forensics report is a summary of your findings. If your case goes to trial, your testimony can, and usually does, involve far more detail than is in the report.
A
True
B
FalseCorrect Answer
QUESTION 23 OF 41
Which section of a digital forensics report would include using the best practices of taking lots of screenshots, use built-in logging options of your digital forensics tools, and exporting key data items into a .csv or .txt file?
A
Overview & Case Summary
B
Forensic Acquisition & Examination Preparation
C
Findings & AnalysisCorrect Answer
D
Conclusion
QUESTION 24 OF 41
Which types of files are appropriate subjects for forensic analysis?
A
Data files
B
Image and video files
C
Application files
D
All of the aboveCorrect Answer
QUESTION 25 OF 41
Deleting a file results in what action by most operating systems?
A
The memory registers used by the file are erased and marked as available for new storage.
B
The file is copied to a trash or recycle folder and the original memory registers are erased.
C
The memory registers used by the file are marked as available for new storage but are otherwise not changed.Correct Answer
D
Random data is immediately copied into the memory registers used by the file to obfuscate the previous contents.
QUESTION 26 OF 41
Forensic analysis should always be conducted on a copy of the original data. What type of copying is appropriate for getting data from a live system that cannot be taken offline?
A
An incremental backup
B
A logical backupCorrect Answer
C
A disk-to-file backup
D
A disk-to-disk backup
QUESTION 27 OF 41
How does a forensic analysis use hash sets acquired from NIST)s Software Reference Library project?
A
They can quickly eliminate known good operating system and application files from consideration.Correct Answer
B
They provide a record of known encrypted malware.
C
Hashes will help you quickly zero in on deleted files.
D
They are useful in identifying files that were created outside the United States.
QUESTION 28 OF 41
Which three (3) of the following data types are considered non-volatile? (Select 3)
A
Dump filesCorrect Answer
B
Swap filesCorrect Answer
C
Free space
D
LogsCorrect Answer
QUESTION 29 OF 41
Configuration files are considered which data type?
A
Static
B
Volatile
C
Dynamic
D
Non-volatileCorrect Answer
QUESTION 30 OF 41
True or False. When collecting forensic data from a running system, you should always attempt to collect non-volatile data first.
A
True
B
FalseCorrect Answer
QUESTION 31 OF 41
Which of these applications would likely be of the least interest in a forensic analysis?
A
Patch filesCorrect Answer
B
Chat
C
Email
D
Web host data
QUESTION 32 OF 41
The Internet layer of the TCP/IP stack, also known as the Network layer in the OSI model, contains which two (2) protocols that are very useful to a forensic investigation? (Select 2)
A
UDP
B
IPv4 / IPv6Correct Answer
C
LDAP
D
ICMPCorrect Answer
QUESTION 33 OF 41
Which device would you inspect if you were looking for event data correlated across a number of different network devices?
A
Firewall
B
Remote access serverCorrect Answer
C
Packet sniffer
D
Intrusion detection system
QUESTION 34 OF 41
Which of these sources might require a court order in order to obtain the data for forensic analysis?
A
Intrusion detection systems
B
System Event Management systems
C
ISP recordsCorrect Answer
D
Firewalls
QUESTION 35 OF 41
According to NIST, the four (4) steps of the forensic process include which? (Select 4)
A
ExaminationCorrect Answer
B
Preserving
C
ReportingCorrect Answer
D
Investigating
E
AnalysisCorrect Answer
F
CollectionCorrect Answer
QUESTION 36 OF 41
What are the three (3) main hurdles that must be overcome when examining data? (Select 3)
A
Dealing with a sea of data. A single hard drive will contains many thousands of files that are not relevant to our investigation.Correct Answer
B
Selecting the most effective tools to help with the searching and filtering of data.Correct Answer
C
Bypassing controls such as operating system and encryption passwords.Correct Answer
D
Not tripping malware booby traps that were setup to prevent examination of data.
QUESTION 37 OF 41
True or False. Only data files can be effectively analyzed during a forensic analysis.
A
True
B
FalseCorrect Answer
QUESTION 38 OF 41
What does file metadata known as “MAC” data stand for in the context of a forensic analysis?
A
Machine Access Control
B
Metadata associated with i/OS files
C
Machine Allocated Content
D
Modification, Access and Creation timesCorrect Answer
QUESTION 39 OF 41
Which operating system has a “Target Disk Mode” that allows a forensic investigator to easily make a copy of the target hard drive?
A
Mac OS XCorrect Answer
B
Microsoft Window
C
Linux
D
UNIX
QUESTION 40 OF 41
Which device would you inspect if you were looking for failed attempts to penetrate your company’s network?
A
FirewallCorrect Answer
B
Intrusion detection system
C
Packet sniffer
D
Remote access server
QUESTION 41 OF 41
How does a forensic analysis use hash sets acquired from NIST’s Software Reference Library project?
A
They can quickly eliminate known good operating system and application files from consideration.Correct Answer
B
They provide a record of known encrypted malware.
C
Hashes will help you quickly zero in on deleted files.
D
They are useful in identifying files that were created outside the United States.
Ready to test your recall?
Digital forensics can be defined as the application of science to the identification, collection, examination, and analysis of what?