Quiz 3 CJUS 363
Question 1
2 out of 2 points
Computer-stored records are data the system maintains, such as system log files and proxy server logs.
Selected
Answer:
Fals
e
Question 2
2 out of 2 points
An emergency situation under the PATRIOT Act is defined as the immediate risk of death or personal
injury, such as finding a bomb threat in an e-mail.
Selected
Answer:
Tru
e
Question 3
2 out of 2 points
State public disclosure laws apply to state records, but FOIA allows citizens to request copies of
public documents created by federal agencies.
Selected
Answer:
Tru
e
Question 4
2 out of 2 points
To investigate employees suspected of improper use of company digital assets, a company policy
statement about misuse of digital assets allows corporate investigators to conduct covert surveillance
with little or no cause, and access company computer systems and digital devices without a warrant.
Selected
Answer:
Tru
e
Question 5
2 out of 2 points
The Fourth Amendment states that only warrants "particularly describing the place to be searched and
the persons or things to be seized" can be issued. The courts have determined that this phrase means a
warrant can authorize a search of a specific place for anything.
Selected
Answer:
Fals
e
Question 6
2 out of 2 points
The physical data copy subfunction exists under the ______________ function.
Selected
Answer:
a.
acquisition
Question 7
2 out of 2 points
A keyword search is part of the analysis process within what forensic function?
Selected
Answer:
a.
extraction
Question 8
2 out of 2 points
In general, what would a lightweight forensics workstation consist of?
Selected
Answer:
a.
A laptop computer built into a carrying case with a small selection of peripheral
options
Question 9
2 out of 2 points
Which of the following options is not a subfunction of extraction?
Selected
Answer:
a.
logical data copy
Question 10
2 out of 2 points
What is the goal of the NSRL project, created by NIST?
Selected
Answer:
d.
Collect known hash values for commercial software and OS files using SHA
hashes.
Question 11
2 out of 2 points
Physically copying the entire drive is the only type of data-copying method used in software
acquisitions.
Selected
Answer:
Fals
e
Question 12
2 out of 2 points
ISO standard 27037 states that the most important factors in data acquisition are the DEFR's
competency and the use of validated tools.
Selected
Answer:
Tru
e
Question 13
2 out of 2 points
All forensics acquisition tools have a method for verification of the data-copying process that
compares the original drive with the image.
Selected
Answer:
Tru
e
Question 14
2 out of 2 points
_______________ proves that two sets of data are identical by calculating hash values or using
another similar method.
Selected
Answer:
d.
Verification
Question 15
2 out of 2 points
Making a logical acquisition of a drive with whole disk encryption can result in unreadable files.
Selected
Answer:
Fals
e
Question 16
2 out of 2 points
What algorithm is used to decompress Windows files?
Selected
Answer:
a.
Lempel-Ziv
Question 17
2 out of 2 points
What is the purpose of the reconstruction function in a forensics investigation?
Selected
Answer:
c.
Re-create a suspect's drive to show what happened during a crime or incident.
Question 18
2 out of 2 points
In what temporary location below might passwords be stored?
Selected
Answer:
c.
pagefile.sys
Question 19
2 out of 2 points
In what mode do most write-blockers run?
Selected
Answer:
b.
Shell mode
Question 20
2 out of 2 points
What tool below was written for MS-DOS and was commonly used for manual digital investigations?
Selected
Answer:
b.
Norton DiskEdit
Question 21
2 out of 2 points
Software forensics tools are grouped into command-line applications and GUI applications
Selected
Answer:
Tru
e
Question 22
2 out of 2 points
Reconstructing fragments of files that have been deleted from a suspect drive, is known as
____________ in North America.
Selected
Answer:
a.
carving
Question 23
2 out of 2 points
What program serves as the GUI front end for accessing Sleuth Kit's tools?
Selected
Answer:
c.
Autopsy
Question 24
2 out of 2 points
The __________ Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack, dcfldd,
MemFetch, and MBoxGrep, and utilizes a KDE interface.
Selected
Answer:
c.
Kali
Question 25
2 out of 2 points
Passwords are typically stored as one-way _____________ rather than in plaintext.
Selected
Answer:
c.
hashes
QU E S T I ON 1
1. Computer-stored records are data the system maintains, such as system log files and proxy server
logs.
True
False
2 points
QU E S T I ON 2
1. An emergency situation under the PATRIOT Act is defined as the immediate risk of death or
personal injury, such as finding a bomb threat in an e-mail.
True
False
2 points
QU E S T I ON 3
1. State public disclosure laws apply to state records, but FOIA allows citizens to request copies of
public documents created by federal agencies.
True
False
2 points
QU E S T I ON 4
1. To investigate employees suspected of improper use of company digital assets, a company policy
statement about misuse of digital assets allows corporate investigators to conduct covert
surveillance with little or no cause, and access company computer systems and digital devices
without a warrant.
True
False
2 points
QU E S T I ON 5
1. The Fourth Amendment states that only warrants "particularly describing the place to be searched
and the persons or things to be seized" can be issued. The courts have determined that this phrase
means a warrant can authorize a search of a specific place for anything.
True
False
2 points
QU E S T I ON 6
1. The physical data copy subfunction exists under the ______________ function.
a
.
acquisition
b
.
validation / verification
c
.
reporting
d
.
extraction
2 points
QU E S T I ON 7
1. A keyword search is part of the analysis process within what forensic function?
a
.
extraction
b
.
reconstruction
c
.
acquisition
d
.
reporting
2 points
QU E S T I ON 8
1. In general, what would a lightweight forensics workstation consist of?
a
.
A laptop computer built into a carrying case with a small selection of peripheral options
b
.
A laptop computer with almost as many bays and peripherals as a tower
c
.
A tower with several bays and many peripheral devices
d
.
A tablet with peripherals and forensics apps
2 points
QU E S T I ON 9
1. Which of the following options is not a subfunction of extraction?
a
.
logical data copy
b
.
decrypting
c
.
bookmarking
d
.
carving
2 points
QU E S T I ON 1 0
1. What is the goal of the NSRL project, created by NIST?
a
.
Create hash values for illegal files and distribute the information to law
enforcement.
b
.
Search for collisions in hash values, and contribute to fixing hashing programs.
c
.
Collect known hash values for commercial software and OS files using MD5 hashes.
d
.
Collect known hash values for commercial software and OS files using SHA hashes.
2 points
QU E S T I ON 1 1
1. Physically copying the entire drive is the only type of data-copying method used in software
acquisitions.
True
False
2 points
QU E S T I ON 1 2
1. ISO standard 27037 states that the most important factors in data acquisition are the DEFR's
competency and the use of validated tools.
True
False
2 points
QU E S T I ON 1 3
1. All forensics acquisition tools have a method for verification of the data-copying process that
compares the original drive with the image.
True
False
2 points
QU E S T I ON 1 4
1. _______________ proves that two sets of data are identical by calculating hash values or using
another similar method.
a
.
Validation
b
.
Integration
c
.
Compilation
d
.
Verification
2 points
QU E S T I ON 1 5
1. Making a logical acquisition of a drive with whole disk encryption can result in unreadable files.
True
False
2 points
QU E S T I ON 1 6
1. What algorithm is used to decompress Windows files?
a
.
Lempel-Ziv
b
.
Shannon-Fano
c
.
Zopfli
d
.
Fibonacci
2 points
QU E S T I ON 1 7
1. What is the purpose of the reconstruction function in a forensics investigation?
a
.
Prove that two sets of data are identical.
b
.
Generate reports or logs that detail the processes undertaken by a forensics investigator.
c
.
Re-create a suspect's drive to show what happened during a crime or incident.
d
.
Copy all information from a suspect's drive, including information that may have been
hidden.
2 points
QU E S T I ON 1 8
1. In what temporary location below might passwords be stored?
a
.
system32.dll
b
.
CD-ROM drive
c
.
pagefile.sys
d
.
Windows registry
2 points
QU E S T I ON 1 9
1. In what mode do most write-blockers run?
a
.
BIOS mode
b
.
Shell mode
c
.
GUI mode
d
.
RW mode
2 points
QU E S T I ON 2 0
1. What tool below was written for MS-DOS and was commonly used for manual digital
investigations?
a
.
ByteBack
b
.
Norton DiskEdit
c
.
DataLifter
d
.
SMART
2 points
QU E S T I ON 2 1
1. Software forensics tools are grouped into command-line applications and GUI applications
True
False
2 points
QU E S T I ON 2 2
1. Reconstructing fragments of files that have been deleted from a suspect drive, is known as
____________ in North America.
a
.
carving
b
.
salvaging
c
.
sculpting
d
.
scraping
2 points
QU E S T I ON 2 3
1. What program serves as the GUI front end for accessing Sleuth Kit's tools?
a
.
KDE
b
.
SMART
c
.
Autopsy
d
.
DetectiveGUI
2 points
QU E S T I ON 2 4
1. The __________ Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack,
dcfldd, MemFetch, and MBoxGrep, and utilizes a KDE interface.
a
.
Arch
b
.
Ubuntu
c
.
Kali
d
.
Helix3
2 points
QU E S T I ON 2 5
1. Passwords are typically stored as one-way _____________ rather than in plaintext.
a
.
variables
b
.
hex values
c
.
hashes
d
.
slack spaces