Quiz 3 CJUS 363
•
Question 1
2 out of 2 points
Computer-stored records are data the system maintains, such as system log files and proxy server logs.
Selecte
d
Answer
:
Fal
s
e
•
Question
2
2 out of 2
points
An emergency situation under the PATRIOT Act is defined as the immediate risk of death or personal
injury, such as finding a bomb threat in an e-mail.
Selecte
d
Answer
:
Tr
u
e
•
Question
3
2 out of 2
points
State public disclosure laws apply to state records, but FOIA allows citizens to request copies of
public documents created by federal agencies.
Selecte
d
Answer
:
Tr
u
e
•
Question
4
2 out of 2
points
To investigate employees suspected of improper use of company digital assets, a company policy
statement about misuse of digital assets allows corporate investigators to conduct covert surveillance
with little or no cause, and access company computer systems and digital devices without a warrant.
Selecte
d
Answer
:
Tr
u
e
•
Question
5
2 out of 2
points
The Fourth Amendment states that only warrants "particularly describing the place to be searched and
the persons or things to be seized" can be issued. The courts have determined that this phrase means
a warrant can authorize a search of a specific place for anything.
Selecte
d
Answer
:
Fal
s
e
•
Question 6
The physical data copy subfunction exists under the function.
2 out of 2
points
Selected
Answer:
•
Question
7
a.
acquisition
2 out of 2
points
A keyword search is part of the analysis process within what forensic function?
Selected
Answer:
•
Question
8
a.
extraction
2 out of 2
points
In general, what would a lightweight forensics workstation consist of?
Selecte
d
Answer
:
a.
A laptop computer built into a carrying case with a small selection of peripheral
options
•
Question 9
Which of the following options is not a subfunction of extraction?
2 out of 2
points
Selecte
d
Answer:
a.
logical data copy
•
Question 10
What is the goal of the NSRL project, created by NIST?
2 out of 2
points
Selecte
d
Answer
:
d.
Collect known hash values for commercial software and OS files using SHA
hashes.
•
Question
11
2 out of 2
points
Physically copying the entire drive is the only type of data-copying method used in software
acquisitions.
Selecte
d
Answer
:
Fal
s
e
•
Question
12
2 out of 2
points
ISO standard 27037 states that the most important factors in data acquisition are the DEFR's
competency and the use of validated tools.
Selecte
d
Answer
:
Tr
u
e
•
Question
13
2 out of 2
points
All forensics acquisition tools have a method for verification of the data-copying process that
compares the original drive with the image.
Selecte
d
Answer
:
T
r
u
e
•
Question
14
2 out of 2
points
proves that two sets of data are identical by calculating hash values or
using another similar method.
Selecte
d
Answer:
d.
Verification
•
Question
15
2 out of 2
points
Making a logical acquisition of a drive with whole disk encryption can result in unreadable files.
Selecte
d
Answer
:
Fal
s
e
•
Question 16
What algorithm is used to decompress Windows files?
2 out of 2
points
Selecte
d
Answer:
a.
Lempel-Ziv
•
Question 17
What is the purpose of the reconstruction function in a forensics investigation?
2 out of 2
points
Selecte
d
Answer:
c.
Re-create a suspect's drive to show what happened during a crime or incident.
•
Question 18
In what temporary location below might passwords be stored?
2 out of 2
points
Selecte
d
Answer:
c.
pagefile.sys
•
Question 19
In what mode do most write-blockers run?
2 out of 2
points
Selecte
d
Answer:
b.
Shell mode
•
Question
20
2 out of 2
points
What tool below was written for MS-DOS and was commonly used for manual digital investigations?
Selecte
d
Answer:
b.
Norton DiskEdit
•
Question
21
2 out of 2
points
Software forensics tools are grouped into command-line applications and GUI applications
Selecte
d
Answer
:
Tr
u
e
•
Question 22
2 out of 2
points
Reconstructing fragments of files that have been deleted from a suspect drive, is known as
in North America.
Selecte
d
Answer:
a.
carving
•
Question 23
What program serves as the GUI front end for accessing Sleuth Kit's tools?
2 out of 2
points
Selecte
d
Answer:
c.
Autopsy
•
Question
24
2 out of 2
points
The Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack, dcfldd,
MemFetch, and MBoxGrep, and utilizes a KDE interface.
Selecte
d
Answer:
c.
Kali
•
Question 25
Passwords are typically stored as one-way rather than in plaintext.
2 out of 2
points
Selecte
d
Answer:
c.
hashes
QUESTION 1
1. Computer-stored records are data the system maintains, such as system log files and proxy
server logs.
True
False
2 points
QUESTION 2
1. An emergency situation under the PATRIOT Act is defined as the immediate risk of death or
personal injury, such as finding a bomb threat in an e-mail.
True
False
2 points
QUESTION 3
1. State public disclosure laws apply to state records, but FOIA allows citizens to request copies of
public documents created by federal agencies.
True
False
2 points
QUESTION 4
1. To investigate employees suspected of improper use of company digital assets, a company policy
statement about misuse of digital assets allows corporate investigators to conduct covert
surveillance with little or no cause, and access company computer systems and digital devices
without a warrant.
True
False
2 points
QUESTION 5
1. The Fourth Amendment states that only warrants "particularly describing the place to be searched
and the persons or things to be seized" can be issued. The courts have determined that this phrase
means a warrant can authorize a search of a specific place for anything.
True
False
QUESTION 6
1. The physical data copy subfunction exists under the function.
a acquisition
.
b validation / verification
.
c reporting
.
d extraction
.
QUESTION 7
1. A keyword search is part of the analysis process within what forensic function?
a extraction
.
b reconstruction
.
2 points
2 points
c acquisition
.
d reporting
.
QUESTION 8
1. In general, what would a lightweight forensics workstation consist of?
2 points
a A laptop computer built into a carrying case with a small selection of peripheral options
.
b A laptop computer with almost as many bays and peripherals as a tower
.
c A tower with several bays and many peripheral devices
.
d A tablet with peripherals and forensics apps
.
QUESTION 9
1. Which of the following options is not a subfunction of extraction?
a logical data copy
.
b decrypting
.
c bookmarking
.
d carving
.
QUESTION 10
1. What is the goal of the NSRL project, created by NIST?
a Create hash values for illegal files and distribute the information to law
2 points
2 points
. enforcement.
b Search for collisions in hash values, and contribute to fixing hashing programs.
.
c Collect known hash values for commercial software and OS files using MD5 hashes.
.
d Collect known hash values for commercial software and OS files using SHA hashes.
.
2 points
QUESTION 11
1. Physically copying the entire drive is the only type of data-copying method used in
software acquisitions.
True
False
2 points
QUESTION 12
1. ISO standard 27037 states that the most important factors in data acquisition are the DEFR's
competency and the use of validated tools.
True
False
2 points
QUESTION 13
1. All forensics acquisition tools have a method for verification of the data-copying process that
compares the original drive with the image.
True
False
2 points
QUESTION 14
1. proves that two sets of data are identical by calculating hash values or
using another similar method.
a Validation
.
b Integration
.
c Compilation
.
d Verification
.
2 points
QUESTION 15
1. Making a logical acquisition of a drive with whole disk encryption can result in unreadable files.
True
False
QUESTION 16
1. What algorithm is used to decompress Windows files?
a Lempel-Ziv
.
b Shannon-Fano
.
c
Zopfli
.
d Fibonacci
.
QUESTION 17
1. What is the purpose of the reconstruction function in a forensics investigation?
a Prove that two sets of data are identical.
.
2 points
2 points
b Generate reports or logs that detail the processes undertaken by a forensics investigator.
.
c Re-create a suspect's drive to show what happened during a crime or incident.
.
d Copy all information from a suspect's drive, including information that may have been
. hidden.
2 points
QUESTION 18
1. In what temporary location below might passwords be stored?
a system32.dll
.
b CD-ROM drive
.
c pagefile.sys
.
d Windows registry
.
QUESTION 19
1. In what mode do most write-blockers run?
a BIOS mode
.
b Shell mode
.
c GUI mode
.
2 points
d RW mode
.
QUESTION 20
2 points
1. What tool below was written for MS-DOS and was commonly used for manual
digital investigations?
a ByteBack
.
b Norton DiskEdit
.
c DataLifter
.
d SMART
.
2 points
QUESTION 21
1. Software forensics tools are grouped into command-line applications and GUI applications
True
False
2 points
QUESTION 22
1. Reconstructing fragments of files that have been deleted from a suspect drive, is known as
in North America.
a carving
.
b salvaging
.
c sculpting
.
d scraping
.
2 points
QUESTION 23
1. What program serves as the GUI front end for accessing Sleuth Kit's tools?
a
KDE
.
b SMART
.
c Autopsy
.
d DetectiveGUI
.
2 points
QUESTION 24
1. The Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack,
dcfldd, MemFetch, and MBoxGrep, and utilizes a KDE interface.
a
Arch
.
b Ubuntu
.
c
Kali
.
d Helix3
.
2 points
QUESTION 25
1. Passwords are typically stored as one-way rather than in plaintext.
a variables
.
b hex values
.
c
hashes
.
d slack spaces
.