1 / 46100%
CJUS 363 CYBER
Quiz 1
Question 1
2 out of 2 points
When conducting a digital forensics analysis under rules for an
attorney, you must keep all findings confidential.
Selected Answer: attorney-client privilege (ACP)
Question 2
is not one of the functions of the investigations triad.
Selected Answer: b.
Data recovery
Question 3
How should backups be stored and maintained?
Selected
Answer:
2 out of 2 points
2 out of 2 points
Response
Feedback:
Backups should be kept in the lab or on location while any previous or
present carbon copies of the backups should be placed in a secured off
stile location as a precaution should anything happen to the pack of backups
kept on location.
[None Given]
Question 4
0 out of 2 points
Why is confidentiality critical in a corporate environment during and after an investigation of
a terminated employee?
Selected
Answer:
Response
Feedback:
[None Given]
Agreements may exist to ensure the confidentiality of the reasons for
termination, or the termination may be represented as a resignation or a layoff in
exchange for no bad references. Disseminating the information could make the
company liable for breach of contract.
Question 5
2 out of 2 points
Typically, the requires a bootable DVD or USB flash drive that runs an
independent OS in a suspect computer's RAM, with the goal of preserving data during an
acquisition.
Selected Answer: software write-blocker
Question 6
2 out of 2 points
When creating a new forensics lab, what are some questions that should be considered when
calculating the budget required? List at least three questions.
Selected
Answer:
Response
Feedback:
There are thirteen questions that should be considered when calculating the
budget required for starting a new forensics lab according to the textbook. Five
of the questions that should be considered are will there be a need for more than
one lab, how many examiners will need to be hired, how much it will cost to
train each examiner per year, how much it will cost to build a secure lab and will
the lab need to have an alarm system installed.
[None Given]
Question 7
is a specialized viewer software program.
Selected Answer: d.
IrfanView
Question 8
The is not one of the three stages of a typical criminal case.
Selected Answer: a.
civil suit
Question 9
2 out of 2 points
2 out of 2 points
2 out of 2 points
Which amendment to the U.S. Constitution protects everyone's right to be secure in their
person, residence, and property from search and seizure?
Selected Answer: b.
Fourth Amendment
Question 10
can be used to restore backup files directly to a workstation.
Selected Answer: a.
Norton Ghost
Question 11
2 out of 2 points
2 out of 2 points
are generated at the federal, state, and local levels to show the types and
frequency of crimes committed.
Selected Answer: Uniform Crime Reports
Question 12
2 out of 2 points
is responsible for creating and monitoring lab policies for staff, and provides a safe
and secure workplace for staff and evidence.
Selected Answer: a.
The lab manager
Question 13
2 out of 2 points
A forensics lab should maintain a paper or electronic sign-in log for all visitors. What
information should be in this log?
Selected
Answer:
Response
Feedback:
Visitor logs for forensic labs should ask and have the following type of
information on the logs. That type of information should be the visitors name,
the date of the visit, time of arrival and departure, reason for the visit, the name
of the lab employ receiving or expecting the visitor and the name of any
authorized personal that escorted the visitor.
[None Given]
Question 14
2 out of 2 points
A disaster recovery plan ensures that workstations and file servers can be restored to their
original condition in the event of a catastrophe.
Selected Answer: True
Question 15
2 out of 2 points
must be included in an affidavit to support an allegation in order to justify a warrant.
Selected Answer: c.
Exhibits
Question 16
How often should hardware be replaced within a forensics lab?
Selected Answer: c.
Every 12 to 18 months
Question 17
Which option below is not a recommendation for securing storage containers?
Selected Answer: c.
2 out of 2 points
2 out of 2 points
Rooms with evidence containers should have a secured wireless network.
Question 18
What is the difference between an interview and an interrogation? 2 out of 2 points
Selected
Answer:
Response
Feedback:
Interviews are conducted by authorities to discusses with and find relevant
information from victims or witness while making the victims and witness feel
comfortable and in a more friendly and relaxed environment. Interrogations are
conducted by authorities with to get a confession out of the suspect and build the
case of the suspects guilt in a presentable and proper format for the
District attorney.
[None Given]
Question 19
What can be done to help prevent the buildup of static electricity? 2 out of 2 points
Selected
Answer: A couple different ways to prevent the buildup of static electricity are anti-static
sprays or liquids, having anti-static pads around electronic work benches or
stations, floors or carpets should be kept cleaned at least one or twice a week to
prevent the buildup of dust which can cause static electricity.
Response
Feedback: [None Given]
Question 20
2 out of 2 points
After a judge approves and signs a search warrant, the is responsible for the
collection of evidence as defined by the warrant.
Selected Answer: d.
Digital Evidence First Responder
Question 21
0 out of 2 points
A(n) acts as an evidence locker or safe to preserve the integrity of
evidence.
Selected Answer: Secure Facility
Question 22
What is a bit-stream image?
Selected
Answer:
2 out of 2 points
Response
Feedback:
A bit-stream image are files that contain the bit-stream copy of all data that is
from a disk or disk partition and bit-stream image is commonly referred to as
image, image save or image file. the bit-stream image is an exact copy of all
data from a targeted disk that was transferred over to a new disk that is similar
to or the exact same manufacture or model as the targeted or evidence disk.
[None Given]
Question 23
2 out of 2 points
After the evidence has been presented in a trial by jury, the jury must deliver a(n) .
Selected Answer: d.
verdict
Question 24
In what year was the Computer Fraud and Abuse Act passed? 2 out of 2 points
Selected Answer: a.
1986
Question 25
2 out of 2 points
If a police officer or investigator has sufficient cause to support a search warrant,
the prosecuting attorney might direct him or her to submit a(n) .
Selected Answer: b.
affidavit
Quiz 2
Question 1
2 out of 2 points
What third party encryption tool creates a virtual encrypted volume, which is a file mounted
as though it were a disk drive?
Selected Answer: c.
TrueCrypt
Question 2
2 out of 2 points
are made up of one or more platters coated with magnetic material, and data is
stored in a particular way.
Selected Answer: Disk drives
Question 3
The ImageUSB utility can be used to create a bootable flash drive.
Selected Answer: True
Question 4
2 out of 2 points
2 out of 2 points
The purpose of a is to provide a mechanism for recovering files encrypted
with EFS if there's a problem with the user's original private key.
Selected Answer: recovery cert
Question 5
FTK Imager software can acquire a drive's host protected area.
Selected Answer: False
Question 6
2 out of 2 points
2 out of 2 points
FAT32 is used on older Microsoft OSs, such as MS-DOS 3.0 through 6.22, Windows 95
(first release), and Windows NT 3.3 and 4.0.
Selected Answer: False
Question 7
The is the device that reads and writes data to a drive.
Selected Answer: head
Question 8
2 out of 2 points
2 out of 2 points
A forensics investigator should verify that acquisition tools can copy data in the HPA of a disk
drive.
Selected Answer: True
Question 9
2 out of 2 points
A Master Boot Record (MBR) partition table marks the first partition starting at what offset?
Selected Answer: a.
0x1BE
Question 10
2 out of 2 points
When two files with different contents generate the same digital fingerprint using a
hashing function, a(n) has occurred.
Selected Answer: collision
Question 11
2 out of 2 points
An investigator wants to capture all data on a SATA drive connected to a Linux system. What
should the investigator use for the " if= " portion of the dcfldd command?
Selected Answer: a.
/dev/sda
Question 12
Which option below is not a hashing function used for validation checks?
Selected Answer: c.
RC4
Question 13
What term below describes a column of tracks on two or more disk platters?
Selected Answer: a.
cylinder
Question 14
2 out of 2 points
2 out of 2 points
2 out of 2 points
When using the File Allocation Table (FAT), where is the FAT database typically written to?
Selected Answer: d.
The outermost track
Question 15
2 out of 2 points
is composed of the unused space in a cluster between the end of an active
file's content and the end of the cluster.
Selected Answer: drive slack
Question 16
What command below can be used to decrypt EFS files?
Selected Answer: d.
efsrecvr
Question 17
2 out of 2 points
2 out of 2 points
What term is used to describe a disk's logical structure of platters, tracks, and sectors?
Selected Answer: c.
geometry
Question 18
What is the dd command? 2 out of 2 points
Selected
Answer:
Response
Feedback:
The dd command is the data dump command. The dd command can read and
write from media devices and data files, creates raw format files that most of
the digital forensics analysis tools are capable of reading.
[None Given]
Question 19
2 out of 2 points
When data is deleted on a hard drive, only references to it are removed, which leaves the
original data on unallocated disk space.
Selected Answer: True
Question 20
2 out of 2 points
What metadata record in the MFT keeps track of previous transactions to assist in recovery
after a system failure in an NTFS volume?
Selected Answer: d.
$LogFile
Question 21
2 out of 2 points
Someone who wants to hide data can create hidden partitions or voids- large unused gaps
between partitions on a disk drive. Data that is hidden in partition gaps cannot be retrieved by
forensics utilities.
Selected Answer: False
Question 22
2 out of 2 points
software can sometimes be used to decrypt a drive that is utilizing whole
disk encryption.
Selected Answer: Elcomsoft forensic disk decryptor
Question 23
What registry file contains user account management and security settings?
Selected Answer: c.
SAM.dat
Question 24
2 out of 2 points
2 out of 2 points
Which RAID type provides increased speed and data storage capability, but lacks redundancy?
Selected Answer: b.
RAID 0
Question 25
A typical disk drive stores how many bytes in a single sector?
Selected Answer: d.
512
Quiz 3
Question 1
2 out of 2 points
2 out of 2 points
State public disclosure laws apply to state records, but FOIA allows citizens to request copies
of public documents created by federal agencies.
Selected Answer: True
Question 2
2 out of 2 points
To investigate employees suspected of improper use of company digital assets, a company
policy statement about misuse of digital assets allows corporate investigators to conduct
covert surveillance with little or no cause, and access company computer systems and digital
devices without a warrant.
Selected Answer: True
Question 3
2 out of 2 points
An emergency situation under the PATRIOT Act is defined as the immediate risk of death or
personal injury, such as finding a bomb threat in an e-mail.
Selected Answer: True
Question 4
2 out of 2 points
Computer-stored records are data the system maintains, such as system log files and proxy
server logs.
Selected Answer: False
Question 5
2 out of 2 points
The Fourth Amendment states that only warrants "particularly describing the place to be
searched and the persons or things to be seized" can be issued. The courts have determined
that this phrase means a warrant can authorize a search of a specific place for anything.
Selected Answer: False
Question 6
The physical data copy subfunction exists under the function.
Selected Answer: b.
acquisition
Question 7
2 out of 2 points
2 out of 2 points
Physically copying the entire drive is the only type of data-copying method used in software
acquisitions.
Selected Answer: False
Question 8
What option below is an example of a platform specific encryption tool?
Selected Answer: a.
BitLocker
2 out of 2 points
Question 9
In what temporary location below might passwords be stored?
Selected Answer: c.
pagefile.sys
Question 10
2 out of 2 points
2 out of 2 points
Reconstructing fragments of files that have been deleted from a suspect drive, is known as
in North America.
Selected Answer: a.
carving
Question 11
Passwords are typically stored as one-way rather than in plaintext.
Selected Answer: a.
hashes
Question 12
In general, what would a lightweight forensics workstation consist of?
2 out of 2 points
2 out of 2 points
Selected
Answer: b.
A laptop computer built into a carrying case with a small selection of
peripheral options
Question 13
What algorithm is used to decompress Windows
files? Selected Answer: c.
Lempel-Ziv
Question 14
In what mode do most write-blockers run?
Selected Answer: c.
2 out of 2 points
2 out of 2 points
Shell mode
Question 15
2 out of 2 points
All forensics acquisition tools have a method for verification of the data-copying process that
compares the original drive with the image.
Selected Answer: True
Question 16
Which of the following options is not a subfunction of extraction?
Selected Answer: c.
logical data copy
Question 17
2 out of 2 points
2 out of 2 points
Software forensics tools are grouped into command-line applications and GUI applications
Selected Answer: True
Question 18
What program serves as the GUI front end for accessing Sleuth Kit's tools?
Selected Answer: c.
Autopsy
Question 19
A keyword search is part of the analysis process within what forensic function?
Selected Answer: a.
extraction
Question 20
What hex value is the standard indicator for jpeg graphics files?
Selected Answer: d.
FF D8
2 out of 2 points
2 out of 2 points
2 out of 2 points
Question 21
2 out of 2 points
ISO standard 27037 states that the most important factors in data acquisition are the DEFR's
competency and the use of validated tools.
Selected Answer: True
Question 22
The ProDiscover utility makes use of the proprietary file format.
Selected Answer: a.
.eve
Question 23
2 out of 2 points
2 out of 2 points
Making a logical acquisition of a drive with whole disk encryption can result in unreadable
files.
Selected Answer: False
Question 24
What is the goal of the NSRL project, created by NIST? 2 out of 2 points
Selected
Answer: c.
Collect known hash values for commercial software and OS files using
SHA hashes.
Question 25
2 out of 2 points
proves that two sets of data are identical by calculating hash values or
using another similar method.
Selected Answer: b.
Verification
Midterm Exam
Question 1
1 out of 1 points
What tool, currently maintained by the IRS Criminal Investigation Division and limited to use
by law enforcement, can analyze and read special files that are copies of a disk?
Selected Answer: a.
ILook
Question 2
is not one of the functions of the investigations triad.
Selected Answer: b.
Data recovery
Question 3
1 out of 1 points
1 out of 1 points
In order to qualify for the Certified Computer Crime Investigator, Basic Level certification,
candidates must provide documentation of at least cases in which they participated.
Selected Answer: b.
10
Question 4
The is not one of the three stages of a typical criminal case.
Selected Answer: b.
civil suit
Question 5
Which option below is not a recommendation for securing storage containers?
Selected Answer: b.
1 out of 1 points
1 out of 1 points
Rooms with evidence containers should have a secured wireless network.
Question 6
1 out of 1 points
How long are computing components designed to last in a normal business environment?
Selected Answer: d.
18 to 36 months
Question 7
1 out of 1 points
What certification program, sponsored by ISC 2, requires knowledge of digital forensics,
malware analysis, incident response, e-discovery, and other disciplines related to cyber
investigations?
Selected Answer: a.
Certified Cyber Forensics Professional
Question 8
What percentage of consumers utilize Intel and AMD
PCs? Selected Answer: c.
90
Question 9
1 out of 1 points
1 out of 1 points
If a police officer or investigator has sufficient cause to support a search warrant,
the prosecuting attorney might direct him or her to submit a(n) .
Selected Answer: a.
affidavit
Question 10
1 out of 1 points
In order to qualify for the Certified Computer Forensic Technician, Basic Level certification,
how many hours of computer forensics training are required?
Selected Answer: b.
40
Question 11
1 out of 1 points
Signed into law in 1973, the was/were created to ensure consistency in federal
proceedings.
Selected Answer: d.
Federal Rules of Evidence
Question 12
1 out of 1 points
Which option below is not one of the recommended practices for maintaining a keyed
padlock?
Selected Answer: a.
Use a master key.
Question 13
How often should hardware be replaced within a forensics lab?
Selected Answer: d.
Every 12 to 18 months
Question 14
Which option below is not a standard systems analysis step?
Selected Answer: c.
Share evidence with experts outside of the investigation.
Question 15
1 out of 1 points
1 out of 1 points
1 out of 1 points
After the evidence has been presented in a trial by jury, the jury must deliver a(n) .
Selected Answer: b.
verdict
Question 16
1 out of 1 points
A disaster recovery plan ensures that workstations and file servers can be restored to their
original condition in the event of a catastrophe.
Selected Answer: True
Question 17
1 out of 1 points
After a judge approves and signs a search warrant, the is responsible for the
collection of evidence as defined by the warrant.
Selected Answer: a.
Digital Evidence First Responder
Question 18
Which file system below is utilized by the Xbox gaming system?
Selected Answer: c.
FATX
Question 19
1 out of 1 points
1 out of 1 points
User groups for a specific type of system can be very useful in a forensics investigation.
Selected Answer: True
Question 20
Which Microsoft OS below is the least intrusive to disks in terms of changing
data? Selected Answer: c.
MS-DOS 6.22
Question 21
is not recommended for a digital forensics workstation.
Selected Answer: d.
Remote access software
Question 22
1 out of 1 points
1 out of 1 points
1 out of 1 points
The term describes a database containing informational records about crimes that
have been committed previously by a criminal.
Selected Answer: b.
police blotter
Question 23
1 out of 1 points
Because they are outdated, ribbon cables should not be considered for use within a forensics
lab.
Selected Answer: False
Question 24
1 out of 1 points
In order to qualify for the Advanced Certified Computer Forensic Technician certification,
a candidate must have years of hands-on experience in computer forensics
investigations.
Selected Answer: c.
five
Question 25
1 out of 1 points
Within a computing investigation, the ability to perform a series of steps again and again
to produce the same results is known as .
Selected Answer: a.
repeatable findings
Question 26
1 out of 1 points
is responsible for creating and monitoring lab policies for staff, and provides a safe
and secure workplace for staff and evidence.
Selected Answer: c.
The lab manager
Question 27
Which operating system listed below is not a distribution of the Linux OS?
Selected Answer: a.
Minix
Question 28
1 out of 1 points
1 out of 1 points
According to the National Institute of Standards and Technology (NIST), digital forensics
involves scientifically examining and analyzing data from computer storage media so that it
can be used as evidence in court.
Selected Answer: False
Question 29
Which tool below is not recommended for use in a forensics lab? 1 out of 1 points
Selected Answer: b.
Degausser
Question 30
1 out of 1 points
Which of the following scenarios should be covered in a disaster recovery plan?
Selected Answer: d.
all of the above
Question 31
1 out of 1 points
An evidence custody form does not usually contain .
Selected Answer: b.
a witness list
Question 32
1 out of 1 points
Candidates who complete the IACIS test successfully are designated as a .
Selected Answer: d.
Certified Forensic Computer Examiner (CFCE)
Question 33
1 out of 1 points
In what year was the Computer Fraud and Abuse Act passed?
Selected Answer: b.
1986
Question 34
1 out of 1 points
All suspected industrial espionage cases should be treated as civil case investigations.
Selected Answer: False
Question 35
1 out of 1 points
The is responsible for analyzing data and determining when another specialist should
be called in to assist with analysis.
Selected Answer: b.
Digital Evidence Specialist
Question 36
can be used to restore backup files directly to a workstation.
Selected Answer: c.
Norton Ghost
Question 37
1 out of 1 points
1 out of 1 points
must be included in an affidavit to support an allegation in order to justify a warrant.
Selected Answer: a.
Exhibits
Question 38
1 out of 1 points
The recording of all updates made to a workstation or machine is referred to as configuration
management.
Selected Answer: True
Question 39
Which ISO standard below is followed by the
ASCLD? Selected Answer: a.
17025:2005
Question 40
1 out of 1 points
1 out of 1 points
Which amendment to the U.S. Constitution protects everyone's right to be secure in their
person, residence, and property from search and seizure?
Selected Answer: a.
Fourth Amendment
Question 41
1 out of 1 points
A chain-of-evidence form, which is used to document what has and has not been done with
the original evidence and forensic copies of the evidence, is also known as a(n) .
Selected Answer: b.
evidence custody form
Question 42
describes the characteristics of a safe storage
container. Selected Answer: a.
NISPOM
Question 43
1 out of 1 points
1 out of 1 points
The shielding of sensitive computing systems and prevention of electronic eavesdropping of
any computer emissions is known as FAUST by the U.S. Department of Defense.
Selected Answer: False
Question 44
describes an accusation of fact that a crime has been committed.
Selected Answer: a.
Allegation
Question 45
1 out of 1 points
1 out of 1 points
Linux Live CDs and WinFE disks do not automatically mount hard drives, but can be used to
view file systems.
Selected Answer: True
Question 46
1 out of 1 points
The sale of sensitive or confidential company information to a competitor is known as
.
Selected Answer: a.
industrial espionage
Question 47
is a specialized viewer software program.
Selected Answer: a.
IrfanView
Question 48
1 out of 1 points
1 out of 1 points
If you turn evidence over to law enforcement and begin working under their direction, you
have become an agent of law enforcement, and are subject to the same restrictions on search
and seizure as a law enforcement agent.
Selected Answer: True
Question 49
A TEMPEST facility is designed to accomplish which of the following goals? 1 out of 1 points
Selected
Answer: a.
Shield sensitive computing systems and prevent electronic eavesdropping of
computer emissions.
Question 50
Most digital investigations in the private sector involve misuse of computing
assets. Selected Answer: True
Question 51
What should be included as part of the approval process?
1 out of 1 points
0 out of 2 points
Selected
Answer:
Response
Feedback:
[None Given]
A risk analysis plan should be included describing how the lab will minimize
the risk of litigation. An estimation of how many investigations are anticipated
and how long they will take to complete on average should also be included.
Question 52
How should backups be stored and maintained?
Selected [None Given]
0 out of 2 points
Answer:
Response
Feedback: Backups should be stored where they are easily accessible. At least one copy of
backups should exist on site, and a duplicate copy or previous copy should be
stored off site in a secure facility. Off-site backups should be rotated on a
schedule.
Question 53
0 out of 2 points
What are three questions that should be asked when performing the justification step?
Selected Answer: [None Given]
Response
Feedback:
The following questions are all valid questions during the justification
step:
What type of computing investigation service is needed for your
organization?
Who are the potential customers for this service, and how will it be
budgeted—as an
internal operation (police department or company security department, for
instance) or
an external operation (a for-profit business venture)?
How will you advertise your services to customers?
What time-management techniques will you use?
Where will the initial and sustaining budget for business
operations come from?
Question 54
0 out of 2 points
What information should be recorded every time an evidence container is opened and closed?
Selected
Answer:
Response
Feedback:
[None Given]
A log listing should be made that indicates the date it was opened and the
initials of the authorized person opening the container. The records should be
maintained for at least three years or longer.
Question 55
What can be done to help prevent the buildup of static electricity? 2 out of 2 points
Selected To help prevent the buildup of static electricity labs and workstations should be
Answer: kept clean and cleaned regularly, Humidifiers can be used to help keep the
air moisturized, moisturizing skin to help prevent static electricity by
preventing dry skin rubbing against clothes, try avoiding synthetic rubber
soles in or on shoes, try to wear only cotton or wool material clothes.
Response
Feedback:
[None Given]
Question 56
What is a business case used for? 2 out of 2 points
Selected
Answer:
Response
Feedback:
Business case is created at the start of a project, maintained throughout the
process and reviewed and verified by the projects board or executives. It holds
documents and details that offer an explanation for the reason a project was
created, what objectives there are for it, holds the costs, benefits, risks and
impacts that help executives make decisions regarding the project.
[None Given]
Question 57
2 out of 2 points
A forensics lab should maintain a paper or electronic sign-in log for all visitors. What
information should be in this log?
Selected
Answer:
Response
Feedback:
Information required by labs for all visitors include information such as the
visitors first and last name, the date of their visit, the reason for or the person
they are visiting, they time the visitor arrived and left, what sections the visitor
was in or had access to and etc.
[None Given]
Question 58
List three practices that should be followed when using a keyed padlock. 2 out of 2 points
Selected
Answer:
Response
Feedback:
Have a list of what keys has been assigned to which authorized personal, have
monthly check ins to ensure authorized personal have not lost their keys, change
locks and keys every year and if an authorized personal loses their key replace
all locks and keys to that particular lock immediately or as soon as possible.
[None Given]
Question 59
0.5 out of 2 points
When creating a new forensics lab, what are some questions that should be considered when
calculating the budget required? List at least three questions.
Selected
Answer:
Response
Feedback:
What programs will be needed to in a range of capacities to be prepared for any
potential problem that may arise, what the original or advised budget has been
or is and where to store the backup logs at off site.
[None Given]
Question 60
2 out of 2 points
What is the difference between a Digital Evidence First Responder (DEFR) and a Digital
Evidence Specialist (DES)?
Selected
Answer:
Response
Feedback:
Digital Evidence First Responder (DEFR) is the technician who goes to the
crime scene, appraises the situation and preforms the intake, logging of and
preserves the evidence. Digital Evidence Specialists (DES) investigates the data,
if necessary retrieves other important data and decides if there is a need for
another specialist to help with or examine the data further.
[None Given]
Question 61
1 out of 1 points
Which RAID type provides increased speed and data storage capability, but lacks redundancy?
Selected Answer: b.
RAID 0
Question 62
1 out of 1 points
An investigator wants to capture all data on a SATA drive connected to a Linux system. What
should the investigator use for the " if= " portion of the dcfldd command?
Selected Answer: b.
/dev/sda
Question 63
1 out of 1 points
A forensics investigator should verify that acquisition tools can copy data in the HPA of a disk
drive.
Selected Answer: True
Question 64
The Linux command can be used to write bit-stream data to files.
Selected Answer: b.
dd
Question 65
1 out of 1 points
1 out of 1 points
Hardware and software errors or incompatibilities are a common problem when dealing with
older hard drives.
Selected Answer: True
Question 66
1 out of 1 points
Which RAID type utilizes a parity bit and allows for the failure of one drive without losing
data?
Selected Answer: d.
RAID 5
Question 67
Which technology below is not a hot-swappable technology?
Selected Answer: b.
IDE
Question 68
The ImageUSB utility can be used to create a bootable flash drive.
Selected Answer: True
Question 69
1 out of 1 points
1 out of 1 points
1 out of 1 points
The Linux command can be used to list the current disk devices connected to the
computer.
Selected Answer: c.
fdisk -l
Question 70
1 out of 1 points
creates a virtual volume of a RAID image file, and then makes repairs on the virtual
volume, which can then be restored to the original RAID.
Selected Answer: d.
R-Tools R-Studio
Question 71
1 out of 1 points
When using a target drive that is FAT32 formatted, what is the maximum size limitation
for split files?
Selected Answer: d.
2 GB
Question 72
What is the name of the Microsoft solution for whole disk encryption?
Selected Answer: b.
BitLocker
Question 73
Which option below is not a hashing function used for validation checks?
Selected Answer: c.
RC4
Question 74
1 out of 1 points
1 out of 1 points
1 out of 1 points
A RAID 3 array uses distributed data and distributed parity in a manner similar to a RAID 5
array.
Selected Answer: True
Question 75
FTK Imager software can acquire a drive's host protected area. 1 out of 1 points
Selected Answer: False
Question 76
1 out of 1 points
The term describes rooms filled with extremely large disk systems that are
typically used by large business data centers.
Selected Answer: c.
server farm
Question 77
1 out of 1 points
To investigate employees suspected of improper use of company digital assets, a company
policy statement about misuse of digital assets allows corporate investigators to conduct
covert surveillance with little or no cause, and access company computer systems and digital
devices without a warrant.
Selected Answer: True
Question 78
1 out of 1 points
Computer-stored records are data the system maintains, such as system log files and proxy
server logs.
Selected Answer: False
Question 79
1 out of 1 points
State public disclosure laws apply to state records, but FOIA allows citizens to request copies
of public documents created by federal agencies.
Selected Answer: True
Question 80
1 out of 1 points
The ability to obtain a search warrant from a judge that authorizes a search and seizure
of specific evidence requires sufficient .
Selected Answer: c.
probable cause
Question 81
1 out of 1 points
A is not a private sector organization.
Selected Answer: d.
hospital
Question 82
1 out of 1 points
is the term for a statement that is made by someone other than an actual witness to
the event while testifying at a hearing.
Selected Answer: d.
Hearsay
Question 83
1 out of 1 points
In cases that involve dangerous settings, what kind of team should be used to recover evidence
from the scene?
Selected Answer: b.
HAZMAT
Question 84
1 out of 1 points
Which system below can be used to quickly and accurately match fingerprints in a database?
Selected Answer: c.
Automated Fingerprint Identification System (AFIS)
Question 85
Which of the following is not done when preparing for a case?
Selected Answer: a.
Set up covert surveillance.
Question 86
does not recover data in free or slack space.
Selected Answer: b.
Sparse acquisition
1 out of 1 points
1 out of 1 points
Question 87
1 out of 1 points
The Fourth Amendment states that only warrants "particularly describing the place to be
searched and the persons or things to be seized" can be issued. The courts have determined
that this phrase means a warrant can authorize a search of a specific place for anything.
Selected Answer: False
Question 88
1 out of 1 points
When seizing digital evidence in criminal investigations, whose standards should be
followed?
Selected Answer: c.
U.S. DOJ
Question 89
1 out of 1 points
are a special category of private sector businesses, due to their ability to investigate
computer abuse committed by employees only, but not customers.
Selected Answer: d.
ISPs
Question 90
1 out of 1 points
As a general rule, what should be done by forensics experts when a suspect computer is seized
in a powered-on state?
Selected
Answer: b.
The decision should be left to the Digital Evidence First Responder
(DEFR).
Question 91
1 out of 1 points
Which court case established that it is not necessary for computer programmers to testify in
order to authenticate computer-generated records?
Selected Answer: a.
United States v. Salgado
Question 92
1 out of 1 points
The term is used to describe someone who might be a suspect or someone with
additional knowledge that can provide enough evidence of probable cause for a search warrant
or arrest.
Selected Answer: a.
person of interest
Question 93
1 out of 1 points
If practical, team(s) should collect and catalog digital evidence at a crime scene or
lab.
Selected Answer: a.
one
Question 94
What does FRE stand for?
Selected Answer: c.
Federal Rules of Evidence
Question 95
You must abide by the while collecting evidence.
Selected Answer: c.
Fourth Amendment
Question 96
1 out of 1 points
1 out of 1 points
1 out of 1 points
Someone who wants to hide data can create hidden partitions or voids- large unused gaps
between partitions on a disk drive. Data that is hidden in partition gaps cannot be retrieved by
forensics utilities.
Selected Answer: False
Question 97
1 out of 1 points
FAT32 is used on older Microsoft OSs, such as MS-DOS 3.0 through 6.22, Windows 95
(first release), and Windows NT 3.3 and 4.0.
Selected Answer: False
Question 98
Match each term with the correct definition below:
0.1 out of 1 points
Question Selected
Match
Concentric circles on a disk platter where data is stored. [None Given]
A new file system developed for Windows Server 2012. It allows increased
stability for disk storage and improved features for data recovery and error
checking.
A public/private key encryption first used in Windows 2000 on NTFS-
formatted disks. The file encrypted with a symmetric key, and then a
public/private key is used to encrypt the symmetric key.
[None Given]
c.
Encryption
File System
The device that reads and writes data to a disk drive. [None Given]
The file system that Microsoft created to replace FAT. It uses security
features, allows smaller cluster sizes, and uses Unicode, which makes it a
more versatile system.
A file that specifies the Windows path installation and a variety of other
startup options.
A device driver that allows the OS to communicate with SCSI or ATA drives
that aren't related to the BIOS.
Information contained in ROM that a computer accesses during startup; this
information tells the computer how to access the OS and hard drive.
A 16-bit program that identifies hardware components during startup snd
sends the information to Ntldr.
The original Microsoft file structure database. It's written to the outermost
track of a disk and contains information about each file stored on the drive.
PCs use this to organize files on a disk so that the OS can find the files it
needs.
[None Given]
[None Given]
[None Given]
[None Given]
[None Given]
b.
bootstrap
process
Question 99
1 out of 1 points
A computer stores system configuration and date and time information in the BIOS when
power to the system is off.
Selected Answer: False
Question 100
0 out of 1 points
Each MFT record starts with a header identifying it as a resident or nonresident attribute.
Selected Answer: False
Question 101
0 out of 1 points
All forensics acquisition tools have a method for verification of the data-copying process that
compares the original drive with the image.
Selected Answer: False
Question 102
The physical data copy subfunction exists under the function.
Selected Answer: d.
acquisition
Question 103
Passwords are typically stored as one-way rather than in plaintext.
Selected Answer: a.
variables
Question 104
1 out of 1 points
0 out of 1 points
1 out of 1 points
Reconstructing fragments of files that have been deleted from a suspect drive, is known as
in North America.
Selected Answer: c.
carving
Question 105
What option below is an example of a platform specific encryption tool?
Selected Answer: b.
BitLocker
Question 106
1 out of 1 points
What program serves as the GUI front end for accessing Sleuth Kit's tools?
Selected Answer: c.
Autopsy
Question 107
In general, what would a lightweight forensics workstation consist of?
1 out of 1 points
1 out of 1 points
Selected
Answer: d.
A laptop computer built into a carrying case with a small selection of
peripheral options
Question 108
1 out of 1 points
Physically copying the entire drive is the only type of data-copying method used in software
acquisitions.
Selected Answer: False
Question 109
What is the goal of the NSRL project, created by NIST? 1 out of 1 points
Selected
Answer: d.
Collect known hash values for commercial software and OS files using
SHA hashes.
Question 110
1 out of 1 points
Software forensics tools are grouped into command-line applications and GUI applications
Selected Answer: True
Question 111
The ProDiscover utility makes use of the proprietary file format.
Selected Answer: d.
1 out of 1 points
.eve
Question 112
1 out of 1 points
The Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack,
dcfldd, MemFetch, and MBoxGrep, and utilizes a KDE interface.
Selected Answer: b.
Kali
Question 113
Which of the following options is not a subfunction of extraction?
Selected Answer: d.
logical data copy
Question 114
What is the purpose of the reconstruction function in a forensics investigation?
1 out of 1 points
1 out of 1 points
Selected
Answer: b.
Re-create a suspect's drive to show what happened during a crime or
incident.
Question 115
1 out of 1 points
Making a logical acquisition of a drive with whole disk encryption can result in unreadable
files.
Selected Answer: False
Question 116
1 out of 1 points
Typically, anti-virus tools run hashes on potential malware files, but some advanced
malware uses as a way to hide its malicious code from antivirus tools.
Selected Answer: c.
bit-shifting
Question 117
1 out of 1 points
In which file system can you hide data by placing sensitive or incriminating data in free or
slack space on disk partition clusters?
Selected Answer: d.
FAT
Question 118
1 out of 1 points
What technique is designed to reduce or eliminate the possibility of a rainbow table being
used to discover passwords?
Selected Answer: a.
salted passwords
Question 119
1 out of 1 points
Select the tool below that does not use dictionary attacks or brute force attacks to crack
passwords:
Selected Answer: a.
OSForensics
Question 120
1 out of 1 points
Because attorneys do not have the right of full discovery of digital evidence, it is not possible
for new evidence to come to light while complying with a defense request for full discovery.
Selected Answer: False
Question 121
What letter should be typed into DiskEdit in order to mark a good sector as bad?
Selected Answer: d.
B
Question 122
1 out of 1 points
1 out of 1 points
In order to aid a forensics investigation, a hardware or software can be
utilized to capture keystrokes remotely.
Selected Answer: a.
keylogger
Question 123
1 out of 1 points
Which password recovery method uses every possible letter, number, and character found on a
keyboard?
Selected Answer: c.
brute-force attack
Question 124
1 out of 1 points
One of the most critical aspects of digital forensics is validating digital evidence because
ensuring the integrity of data you collect is essential for presenting evidence in court.
Selected Answer: True
Question 125
Which of the following file systems can't be analyzed by OSForensics?
Selected Answer: c.
XFS
Question 126
1 out of 1 points
1 out of 1 points
Advanced hexadecimal editors offer many features not available in digital forensics tools,
such as hashing specific files or sectors.
Selected Answer: True
Question 127
1 out of 1 points
Many commercial encryption programs use a technology called , which is
designed to recover encrypted data if users forget their passphrases or if the user key is
corrupted after a system failure.
Selected Answer: c.
key escrow
Question 128
1 out of 1 points
The maintains a national database of updated file hash values for
a variety of OSs, applications, and images, but does not list hash values of known illegal files.
Selected Answer: d.
National Software Reference Library
Question 129
Within Windows Vista and later, partition gaps are bytes in length.
Selected Answer: d.
128
Question 130
1 out of 1 points
1 out of 1 points
The AccessData program has a hashing database, , which is available only
with FTK, and can be used to filter known program files from view and contains the hash
values of known illegal files.
Selected Answer: c.
Known File Filter (KFF)
Question 131
1 out of 1 points
A image file containing software is intended to be bit-stream copied to floppy
disks or other external media.
Selected Answer: b.
dd
Question 132
1 out of 1 points
The goal of recovering as much information as possible can result in , in
which an investigation expands beyond the original description because of unexpected
evidence found.
Selected Answer: c.
scope creep
Question 133
1 out of 1 points
Which option below is not a disk management tool?
Selected Answer: d.
HexEdit
Question 134
The term for detecting and analyzing steganography files is .
Selected Answer: c.
steganalysis
Question 135
What format below is used for VMware
images? Selected Answer: b.
.vmdk
Question 136
1 out of 1 points
1 out of 1 points
1 out of 1 points
In Windows, the command can be used to both hide and reveal partitions
within Explorer.
Selected Answer: b.
diskpart
Question 137
A user with programming experience may use an assembler program (also called a 1 out of 1 points
) on a file to scramble bits, in order to secure the information contained inside.
Selected Answer: b.
macro
Question 138
1 out of 1 points
In private sector cases, like criminal and civil cases, the scope is always defined by a search
warrant.
Selected Answer: False
Question 139
1 out of 1 points
When performing a static acquisition, what should be done after the hardware on a suspect's
computer has been inventoried and documented?
Selected
Answer: a.
The hard drive should be removed, if practical, and the system's date and time
values should be recorded from the system's CMOS.
Question 140
1 out of 1 points
The advantage of recording hash values is that you can determine whether data has changed.
Selected Answer: True
Quiz 4
Question 1
2 out of 2 points
Which e-mail recovery program below can recover files from VMware and VirtualPC virtual
machines, as well as ISOs and other types of file backups?
Selected Answer: d.
DataNumen Outlook Repair
Question 2
2 out of 2 points
What service below can be used to map an IP address to a domain name, and then find the
domain name's point of contact?
Selected Answer: a.
ARIN
Question 3
2 out of 2 points
In older versions of exchange, what type of file was responsible for messages formatted with
Messaging Application Programming Interface, and served as the database file?
Selected Answer: c.
.edb
Question 4
One of the most noteworthy e-mail scams was 419, otherwise known as the
.
Selected Answer: a.
Nigerian Scam
Question 5
2 out of 2 points
2 out of 2 points
An Internet e-mail server is generally part of a local network, and is maintained and managed
by an administrator for internal use by a specific company.
Selected Answer: False
Question 6
How can routers be used to determine the path of an e-mail?
Selected
Answer:
2 out of 2 points
Response
Feedback:
The mail packet headers include a history of the journey of e-mails to the
final email inbox destination. As a result of the mail packet headers it is possible
to determine the senders original IP address. Email programs do not normally
display the mail packet headers there is a need to learn how to access these
headers depending on the type of header there are different ways to gain
access to them.
[None Given]
Question 7
Compare and contrast email services on Internet and an intranet. 2 out of 2 points
Selected
Answer: Internet and Intranets have some similarities such as both in their basic programs
are computer networks that allow users to communicate and gain access to
information. They also allow their users use of similar tools that allow
for communications and collaborations. The contrasts betweens these two are the
Internet is available and usable by anyone and the ability to use this resource
anonymously and where as intranets are private networks where there is no
anonymous ability all users are documented and known. The intranet network
allows users to trust the information they see or receive as being honest
information which allows for honest, effective and safe communication and
Response
Feedback:
collaboration through the intranet network. While the internet is available to
everyone for use and most of the information and collaborations that are
received, shared, viewed and worked on by others is near impossible to trust and
can lead to issues.
[None Given]
Question 8
Describe the two different types of Facebook profiles. 0.5 out of 2 points
Selected
Answer:
Response
Feedback:
There are two different types of Facebook profiles are Profiles and Pages.
Facebook Profiles are for individual usage where people can create an account
for their selves and share information about their selves such as interests, photos,
videos, where they currently live and information about bands, singers, tv shows,
movies and etc. that they like. where as pages are created and used by business,
brands, organizations, bands, singers, celebrities, artists and ect. to promote or
connect with their fans, customers, friends, families adn etc.
Facebook has two types of profiles: basic subscriber info and extended
subscriber info (called Neoprint). Basic subscriber info simply tells you the last
time a person logged on, his or her e-mail address and associated mobile
number, and whether the account can be viewed publicly. The Neoprint profile
includes friends, groups, video feeds, and undeleted photos. Typically, this
profile is given to law enforcement only with a warrant.
Question 9
On a UNIX system, where is a user's mail stored by default?
Selected Answer: d.
/home/username/mail
Question 10
2 out of 2 points
2 out of 2 points
E-mail administrators may make use of , which overwrites a log file
when it reaches a specified size or at the end of a specified time frame.
Selected Answer: c.
circular logging
Question 11
Where does the Postfix UNIX mail server store e-mail?
Selected Answer: c.
/var/spool/postfix
Question 12
2 out of 2 points
2 out of 2 points
Similar to ARIN, the can be used to find a domain's IP address and point
of contact.
Selected Answer: www.internic.com
Question 13
2 out of 2 points
Committing crimes with e-mail is uncommon, and investigators are not generally tasked with
linking suspects to e-mail.
Selected Answer: False
Question 14
In what state is sending unsolicited e-mail illegal?
Selected Answer: a.
Washington
Question 15
2 out of 2 points
2 out of 2 points
What type of Facebook profile is usually only given to law enforcement with a warrant?
Selected Answer: d.
Neoprint profile
Question 16
In an e-mail address, everything before the @ symbol represents the domain
name. Selected Answer: False
Question 17
2 out of 2 points
2 out of 2 points
The includes logging instructions and is located within
the /etc directory. It determines what happens to an e-mail when it is logged: the event,
priority level, and the action taken.
Selected Answer: syslog.conf
Question 18
Which option below is the correct path to the sendmail configuration file?
Selected Answer: d.
/etc/mail/sendmail.cf
Question 19
2 out of 2 points
2 out of 2 points
Many web-based e-mail providers offer services, such as
Yahoo! Messenger and Google Talk.
Selected Answer: Instant Messaging (IM)
Question 20
2 out of 2 points
What kind of files are created by Exchange while converting binary data to readable text in
order to prevent loss of data?
Selected Answer: a.
.tmp
Question 21
2 out of 2 points
Select the program below that can be used to analyze mail from Outlook, Thunderbird, and
Eudora.
Selected Answer: c.
Fookes Aid4Mail
Question 22
What information is not typically included in an e-mail header?
Selected Answer: c.
The sender's physical location
2 out of 2 points
Question 23
2 out of 2 points
The Pagefile.sys file on a computer can contain message fragments from instant messaging
applications.
Selected Answer: True
Question 24
2 out of 2 points
The DomainKeys Identified Mail service is a way to verify the names of domains a message is
flowing through and was developed as a way to cut down on spam.
Selected Answer: True
Question 25
2 out of 2 points
Syslog is generally configured to put all e-mail related log information into what file?
Selected Answer: d.
/var/log/maillog
Students also viewed