Cyber Security

profilecjpnwe
assignment_4.docx

Question 1 of 20

5.0 Points

Corporate computer-related investigations that do not employ computer forensic science may result in:

A. the unsuccessful prosecution of a case.

B. allegations of corruption among company officers.

C. the loss of business as well as reputation.

D. allegations of employee harassment.

Reset Selection

Question 2 of 20

5.0 Points

We’ve learned that encryption technology makes recovery of digital evidence increasingly complex. Which of the following would be virtually impossible for an investigator to crack?

A. An encryption program found within the Microsoft Word application

B. An encryption program that can store passwords up to 128 characters

C. A 256-bit encryption program that, among other options, includes the ability for the user to develop their own encryption algorithms

D. A 180-bit encryption program that can encrypt an entire drive

Reset Selection

Question 3 of 20

5.0 Points

Sam the investigator searches for digital evidence directly on the hard drive of a suspect computer. Which one of the cardinal rules of computer investigations has he violated?

A. Failing to have a fellow officer present as he works

B. Failing to document his activity

C. Failing to maintain a chain of custody

D. Failing to work from an image of the suspect hard drive

Reset Selection

Question 4 of 20

5.0 Points

Which area of the hard disk is not dependent on a power source for its continued maintenance and can be changed under certain operating conditions?

A. Semi-permanent storage

B. Volatile memory

C. Read-Only Memory (ROM)

D. Random Access Memory (RAM)

Reset Selection

Question 5 of 20

5.0 Points

On a DOS-based system, which of the following drives is loaded first?

A. Logical, or independent level drives

B. Physical, or machine level drives

C. Device drivers

D. Application drivers

Reset Selection

Question 6 of 20

5.0 Points

What area of a hard disk is extremely important for investigators to understand and search because it may contain remnants of older files or other evidence such as passwords?

A. The primary partition

B. The extended partition

C. The Master Boot Record

D. The file slack

Reset Selection

Question 7 of 20

5.0 Points

Once an investigator can articulate the fixed disk structure and identify the units of data, what part of the system contains the information needed to identify and locate where a file resides?

A. The File Allocation Tables (FAT)

B. The Master Partition Table

C. The Master Boot Record

D. The BIOS

Reset Selection

Question 8 of 20

5.0 Points

Every hard disk has a place where key information is stored about the disk. It also contains the program necessary to load the operating system. This information is stored in the:

A. Basic Input Output System (BIOS).

B. File Allocation Tables (FAT).

C. Windows Help File.

D. Master Boot Record (MBR).

Reset Selection

Question 9 of 20

5.0 Points

A user may corrupt the logical size of a drive to confuse investigators by:

A. reformatting the hard drive.

B. using a sabotage program.

C. hiding entire partitions of the disk.

D. renaming the drive letters.

Reset Selection

Question 10 of 20

5.0 Points

Where would a new employee in the computer forensics lab find the proper method to analyze seized digital evidence?

A. In the lab’s Standard Operating Procedures

B. On the Internet

C. In the lab’s computer library of reference material

D. In a forensics analysis software package

Reset Selection

Question 11 of 20

5.0 Points

Challenges to developing an effective computer forensics science unit include all of the following EXCEPT:

A. developing SOPs that provide valid and legally defensible results.

B. a lack of trained professionals.

C. finding storage for the materials that investigators need.

D. proving the need for such a unit.

Reset Selection

Question 12 of 20

5.0 Points

The allocation of a dedicated space for a lab is needed primarily to:

A. meet the Federal Rules of Evidence.

B. minimize risk of legal issues related to content of some types of digital evidence.

C. protect expensive hardware and other equipment.

D. store digital evidence.

Reset Selection

Question 13 of 20

5.0 Points

Because it enables investigators to bypass the operating system on a suspect hard drive, which of the following is one of the most important forensic software tools in an investigator’s evidence kit?

A. Boot disks

B. Data preservation tools

C. Data analysis tools

D. Data duplication tools

Reset Selection

Question 14 of 20

5.0 Points

Which of the following programs enables an investigator to perfectly duplicate a suspect drive, countering many courtroom defense challenges to the examination of digital evidence?

A. Backup utility programs

B. File recovery programs

C. Imaging programs

D. Data recovery programs

Reset Selection

Question 15 of 20

5.0 Points

Which of the following should also be used as part of the data duplication process to further deflect possible defense challenges as well as ensure preservation of the original evidence?

A. Backup utility software

B. Write-blocking programs

C. DOS-based copy commands

D. Verification programs

Reset Selection

Question 16 of 20

5.0 Points

In addition to programs that are capable of restoring deleted and hidden files on a suspect computer, which of the following data recovery utilities is also a necessity for an effective forensics lab?

A. Encryption programs

B. Password cracking programs

C. Diskcopy programs

D. Stenography programs

Reset Selection

Question 17 of 20

5.0 Points

Of the five general categories of data analysis tools, which of the following is most commonly used by local agencies because it allows the investigator to quickly identify questionable graphics files?

A. Text searching tools

B. File viewers

C. File managers

D. Time/date verification tools

Reset Selection

Question 18 of 20

5.0 Points

Which of the following data analysis tools allows an investigator to not only locate files on a suspect system, but also to search them chronologically?

A. Viewers

B. Indexers

C. Time/data verifiers

D. File managers

Reset Selection

Question 19 of 20

5.0 Points

Following the disposition of a case, the forensics lab should permanently remove criminal contraband from the suspect machine by:

A. using the DOS command “erase” on the suspect drive.

B. utilizing a wiping software program.

C. reformatting the suspect hard drive.

D. manually deleting the suspect files on the suspect system.

Reset Selection

Question 20 of 20

5.0 Points

In addition to hardware and software manuals, every computer crime library should include manuals on operating systems. Which of the following operating system manuals is most essential because most computers operate on this platform?

A. Macintosh

B. Windows XP

C. DOS

D. Linux