As a security analyst, you setup a false survey website that will require users to create a username and a strong password. You send the link to all the employees of the company. What information will you be able to gather?
-
A
The IP address of the employees' computers
-
B
Bank account numbers and the corresponding routing numbers
-
C
The employees network usernames and passwords
-
D
The MAC address of the employees' computers
Reveal answer details
Close answer details
A forensics investigator is studying the Event ID logs on a domain controller for a corporation, following a suspected security breach. He notices that a domain user account was created, then modified, and then added to a group in a very short span of time. The investigator realizes that he must cross-verify the audit policies on the local system to understand if any changes were made to it. Assuming that the investigator has the correct audit policy settings, which of the following Event IDs should he focus on?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following tool creates a bit-by-bit image of an evidence media?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
An investigator is checking a Cisco firewall log that reads as follows: Aug 21 2019 09:16:44: %ASA-1 -106021: Deny ICMP reverse path check from 10.0.0.44 to 10.0.0.33 on interface outside What does %ASA-1-106021 denote?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
The ARP table of a router comes in handy for Investigating network attacks, as the table contains IP addresses associated with the respective MAC addresses. The ARP table can be accessed using the __________command in Windows 7.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following malware analysis involves executing the malware code to know how the code interacts with the host system and its impact on the system?
-
A
-
B
-
C
-
D
Secondary Malware Analysis
Reveal answer details
Close answer details
With the standard Linux second extended file system (Ext2fs), a file is deleted when the inode internal link count reaches ______
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which tool does the investigator use to extract artifacts left by Google Drive on the system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
A rogue/unauthorized access point is one that Is not authorized for operation by a particular firm or network
-
A
-
B
Reveal answer details
Close answer details
Question 10
Single choice
What type of attack sends spoofed UDP packets (instead of ping packets) with a fake source address to the IP broadcast address of a large network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Single choice
What is the name of the standard Linux command that can be used to create bit-stream images?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Multiple choice
The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?
-
A
Any data not yet flushed to the system will be lost
-
B
All running processes will be lost
-
C
The /tmp directory will be flushed
-
D
Power interruption will corrupt the pagefile
Reveal answer details
Close answer details
Question 13
Single choice
LBA (Logical Block Address) addresses data by allotting a ___________to each sector of the hard disk.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Operating System logs are most beneficial for Identifying or Investigating suspicious activities involving a particular host. Which of the following Operating System logs contains information about operational actions performed by OS components?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 15
Single choice
How many characters long is the fixed-length MD5 algorithm checksum of a critical system file?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Digital evidence validation involves using a hashing algorithm utility to create a binary or hexadecimal number that represents the uniqueness of a data set, such as a disk drive or file. Which of the following hash algorithms produces a message digest that is 128 bits long?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
A forensics investigator is searching the hard drive of a computer for files that were recently moved to the Recycle Bin. He searches for files in C:\RECYCLED using a command line tool but does not find anything. What is the reason for this?
-
A
He should search in C:\Windows\System32\RECYCLED folder
-
B
The Recycle Bin does not exist on the hard drive
-
C
The files are hidden and he must use switch to view themThe files are hidden and he must use ? switch to view them
-
D
Only FAT system contains RECYCLED folder and not NTFS
Reveal answer details
Close answer details
Question 18
Single choice
You should make at least how many bit-stream copies of a suspect drive?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 19
Single choice
In an investigation of cybercrime involving advanced persistent threats (APTs), the forensic team faces challenges in managing and interpreting the digital evidence due to the global origin of the crime and the diverse nature of the digital devices involved. The investigator has to select the most effective method to overcome these challenges. What should be the preferred approach?
-
A
Invest in powerful automated tools to handle the high complexity of digital evidence
-
B
Opt for traditional investigation approaches that examine local physical devices
-
C
Improve collaboration with international law enforcement agencies to bridge the gap in jurisdictional boundaries
-
D
Speed up the investigation process by bypassing the need for warrants and authorizations
Reveal answer details
Close answer details
Question 20
Single choice
Choose the layer in iOS architecture that provides frameworks for iOS app development?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
Why is it still possible to recover files that have been emptied from the Recycle Bin on a Windows computer?
-
A
The data is still present until the original location of the file is used
-
B
The data is moved to the Restore directory and is kept there indefinitely
-
C
The data will reside in the L2 cache on a Windows computer until it is manually deleted
-
D
It is not possible to recover data that has been emptied from the Recycle Bin
Reveal answer details
Close answer details
Question 22
Single choice
An EC2 instance storing critical data of a company got infected with malware. The forensics team took the EBS volume snapshot of the affected instance to perform further analysis and collected other data of evidentiary value. What should be their next step?
-
A
They should terminate all instances connected via the same VPC
-
B
They should pause the running instance
-
C
They should keep the instance running as it stores critical data
-
D
They should terminate the instance after taking necessary backup
Reveal answer details
Close answer details
Question 23
Single choice
Which set of anti-forensic tools/techniques allows a program to compress and/or encrypt an executable file to hide attack tools from being detected by reverse-engineering or scanning?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
A large corporation hired an independent marketing firm to manage its email advertising campaign. Subsequently, it was found that the firm wassending commercial emails without including necessary information about how to stop receiving emails in the future. In addition, they failed tohonor the opt-out requests of the recipients within 10 business days. Under the CAN-SPAM Act, which of the following is true?
-
A
Both the corporation and the marketing firm could be held legally responsible for the violation
-
B
Only the corporation would be held legally responsible for the violation
-
C
The marketing firm alone would be held legally responsible for the violation
-
D
Neither the corporation nor the marketing firm would be held legally responsible for the violation
Reveal answer details
Close answer details
Question 25
Single choice
What command-line tool enables forensic investigator to establish communication between an Android device and a forensic workstation in order to perform data acquisition from the device?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
Which of the following technique creates a replica of an evidence media?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
You can interact with the Registry through intermediate programs. Graphical user interface (GUI) Registry editors such as Regedit.exe or Regedt32 exe are commonly used as intermediate programs in Windows 7. Which of the following is a root folder of the registry editor?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
Steven has been given the task of designing a computer forensics lab for the company he works for. He has found documentation on all aspects of how to design a lab except the number of exits needed. How many exits should Steven include in his design for the computer forensics lab?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
Which tool allows dumping the contents of process memory without stopping the process?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
An on-site incident response team is called to investigate an alleged case of computer tampering within their company. Before proceeding with the investigation, the CEO informs them that the incident will be classified as low level. How long will the team have to respond to the incident?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 31
Single choice
During an investigation, Noel found a SIM card from the suspect's mobile. The ICCID on the card is 8944245252001451548. What does the first four digits (89 and 44) in the ICCID represent?
-
A
TAC and industry identifier
-
B
Industry identifier and country code
-
C
Country code and industry identifier
-
D
Issuer identifier number and TAC
Reveal answer details
Close answer details
Question 32
Single choice
Click on the Exhibit button. To test your website for vulnerabilities, you type a quotation mark (') in the username field. After you click OK, you receive the following error message window: What can you infer from this error window?
-
A
SQL injection is not possible
-
B
SQL injection is possible
-
C
The user for line 3306 in the SQL database has a weak password
-
D
The quotation mark (') is a valid username
Reveal answer details
Close answer details
Question 33
Single choice
Jason discovered a file named $RIYG6VR.doc in the C:\$Recycle.Bin\<USER SID>\ while analyzing a hard disk image for the deleted data. What inferences can he make from the file name?
-
A
It is a doc file deleted in seventh sequential order
-
B
RIYG6VR.doc is the name of the doc file deleted from the system
-
C
It is file deleted from R drive
-
D
Reveal answer details
Close answer details
Question 34
Single choice
When reviewing web logs, you see an entry for resource not found in the HTTP status code filed. What is the actual error code that you would see in the log for resource not found?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 35
Single choice
You are using DriveSpy, a forensic tool and want to copy 150 sectors where the starting sector is 1709 on the primary hard drive. Which of the following formats correctly specifies these sectors?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
An Expert witness gives an opinion if:
-
A
The Opinion, inferences or conclusions depend on special knowledge, skill or training not within the ordinary experience of lay jurors
-
B
To define the issues of the case for determination by the finder of fact
-
C
To stimulate discussion between the consulting expert and the expert witness
-
D
To deter the witness form expanding the scope of his or her investigation beyond the requirements of the case
Reveal answer details
Close answer details
Question 37
Single choice
Which of the following information is displayed when Netstat is used with -ano switch?
-
A
-
B
Contents of IP routing table
-
C
-
D
Details of TCP and UDP connections
Reveal answer details
Close answer details
Question 38
Single choice
What must an attorney do first before you are called to testify as an expert?
-
A
Qualify you as an expert witness
-
B
Read your curriculum vitae to the jury
-
C
-
D
Prove that the tools you used to conduct your examination are perfect
Reveal answer details
Close answer details
Question 39
Single choice
To enhance the security and effectiveness of a computer forensic laboratory, the management is considering implementing a series of changes based on best practices. Which measure would NOT be effective or appropriate according to the given information? To enhance the security and effectiveness of a computer forensic laboratory, the management is considering implementing a series of changes based on best practices. Which measure would NOT be effective or appropriate according to the given information?
-
A
Establishing a team of forensic analysts, forensic technicians, lab cybercrime investigators, and lab directors without ensuring their certification pertaining to their job roles
-
B
Seeking ISO/IEC 17025 accreditation which outlines general requirements for the impartiality, competence, and uniform operations of laboratories to conduct tests and/or calibrations, including sampling
-
C
Applying the TEMPEST standards by lining the lab's walls, ceilings, and floors with good metallic conductors to shield workstations from transmitting electromagnetic signals
-
D
Deploying an intrusion alarm system in the lab to provide additional protection and placing closed-circuit cameras in the lab and around its premises for surveillance
Reveal answer details
Close answer details
Question 40
Single choice
Robert needs to copy an OS disk snapshot of a compromised VM to a storage account in different region for further investigation. Which of the following should he use in this scenario?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 41
Single choice
Log management includes all the processes and techniques used to collect, aggregate, and analyze computer-generated log messages. It consists of the hardware, software, network and media used to generate, transmit, store, analyze, and dispose of log data.
-
A
-
B
Reveal answer details
Close answer details
Question 42
Single choice
In a scenario where a potential security incident has occurred on a cloud-based service, and an investigator is brought in to examine the system, what type of data acquisition would likely be beneficial in this situation? Also, explain the volatile data type that might be most interesting to the investigator.
-
A
Live acquisition should be employed to gather dynamic data from the system, concentrating on open les and command history
-
B
Dead acquisition should be used to collect static data from the system, focusing on slack space and swap files
-
C
Live acquisition would be advantageous to acquire volatile data, emphasizing data stored on cloud services and unencrypted containers that arc open on the system
-
D
Dead acquisition should be utilized to capture non-volatile data from the physical hard disk, focusing on unallocated drive space
Reveal answer details
Close answer details
Question 43
Single choice
An investigator is tasked with analyzing metadata from a suspected MAC system in a case of data theft. They have decided to parse the Spotlight database file, store.db. Which of the following tools and steps would be most effective for obtaining recently accessed file details from this MacOS system?
-
A
Running the spotlight_parser Python script on the store.db file to extract file metadata
-
B
Using the OS X Auditor to hash artifacts on the running system
-
C
Implementing the Stellar Data Recovery Professional for Mac to recover lost or deleted data
-
D
Utilizing Memoryze for the Mac to analyze the memory images of the Mac machine
Reveal answer details
Close answer details
Question 44
Single choice
For what purpose do the investigators use tools like iPhoneBrowser, iFunBox, OpenSSHSSH, and iMazing?
-
A
Bypassing iPhone passcode
-
B
-
C
-
D
Copying contents of iPhone
Reveal answer details
Close answer details
Question 45
Single choice
Before you are called to testify as an expert, what must an attorney do first?
-
A
-
B
prove that the tools you used to conduct your examination are perfect
-
C
read your curriculum vitae to the jury
-
D
qualify you as an expert witness
Reveal answer details
Close answer details
Question 46
Single choice
In a high-profile digital forensics investigation, a Computer Hacking Forensic Investigator (CHFI) has successfully secured digital evidence from the crime scene. The investigator must now preserve this evidence for further analysis. Which of the following actions should the investigator prioritize to ensure evidence integrity?
-
A
Use a tag to uniquely identify the evidence and create a chain of custody record
-
B
Brief the press about the types of evidence collected to maintain transparency
-
C
Immediately send the evidence to the forensic laboratory for detailed analysis
-
D
Print out a copy of all digital les to keep as a backup
Reveal answer details
Close answer details
Question 47
Single choice
Which of the following is NOT an anti-forensics technique?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 48
Single choice
Adam is thinking of establishing a hospital in the US and approaches John, a software developer to build a site and host it for him on one of the servers, which would be used to store patient health records. He has learned from his legal advisors that he needs to have the server's log data reviewed and managed according to certain standards and regulations. Which of the following regulations are the legal advisors referring to?
-
A
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
-
B
Payment Card Industry Data Security Standard (PCI DSS)
-
C
Data Protection Act of 2018
-
D
Electronic Communications Privacy Act
Reveal answer details
Close answer details
Question 49
Single choice
Which layer of iOS architecture should a forensics investigator evaluate to analyze services such as Threading, File Access, Preferences, Networking and high-level features?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
Data Files contain Multiple Data Pages, which are further divided into Page Header, Data Rows, and Offset Table. Which of the following is true for Data Rows?
-
A
Data Rows store the actual data
-
B
Data Rows present Page type. Page ID, and so on
-
C
Data Rows point to the location of actual data
-
D
Data Rows spreads data across multiple databases
Reveal answer details
Close answer details
Question 51
Single choice
Your organization is implementing a new database system and has chosen MySQL due to its pluggable storage engine capability and ability to handle parallel write operations securely. You are responsible for selecting the best-suited storage engine for your company's needs, which predominantly involves transactional processing, crash recovery, and high data consistency requirements. What would be the most appropriatechoice?
-
A
InnoDB storage engine, because it supports traditional ACID and crash recovery, and is used in online transaction processing systems
-
B
Memory storage engine, because it offers in-memory tables and implements a hashing mechanism for faster data retrieval
-
C
MyISAM storage engine, because it offers unlimited data storage and high-speed data loads
-
D
BDB storage engine, because it provides an alternative to InnoDB and supports additional transaction methods such as COMMIT and ROLLBACK
Reveal answer details
Close answer details
Question 52
Single choice
Stephen is checking an image using Compare Files by The Wizard, and he sees the file signature is shown as FF D8 FF E1. What is the file type of the image?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 53
Single choice
What is the primary function of the tool CHKDSK in Windows that authenticates the file system reliability of a volume?
-
A
Repairs logical file system errors
-
B
Check the disk for hardware errors
-
C
Check the disk for connectivity errors
-
D
Check the disk for Slack Space
Reveal answer details
Close answer details
Question 54
Single choice
James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testing against his network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 55
Single choice
Daryl, a computer forensics investigator, has just arrived at the house of an alleged computer hacker. Daryl takes pictures and tags all computer and peripheral equipment found in the house. Daryl packs all the items found in his van and takes them back to his lab for further examination. At his lab, Michael his assistant helps him with the investigation. Since Michael is still in training, Daryl supervises all of his work very carefully. Michael is not quite sure about the procedures to copy all the data off the computer and peripheral devices. How many data acquisition tools should Michael use when creating copies of the evidence for the investigation?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 56
Single choice
In Steganalysis, which of the following describes a Known-stego attack?
-
A
The hidden message and the corresponding stego-image are known
-
B
During the communication process, active attackers can change cover
-
C
Original and stego-object are available and the steganography algorithm is known
-
D
Only the steganography medium is available for analysis
Reveal answer details
Close answer details
Question 57
Single choice
While working for a prosecutor, what do you think you should do if the evidence you found appears to be exculpatory and is not being released to the defense?
-
A
Keep the information of file for later review
-
B
-
C
Bring the information to the attention of the prosecutor, his or her supervisor or finally to the judge
-
D
Present the evidence to the defense attorney
Reveal answer details
Close answer details
Question 58
Single choice
When reviewing web logs, you see an entry for resource not found in the HTTP status code field. What is the actual error code that you would see in the log for resource not found?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 59
Single choice
Which cloud model allows an investigator to acquire the instance of a virtual machine and initiate the forensics examination process?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 60
Single choice
It takes _____________ mismanaged case/s to ruin your professional reputation as a computer forensics examiner?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 61
Single choice
How many sectors will a 125 KB file use in a FAT32 file system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 62
Single choice
Investigator Janet comes across a suspicious Windows registry key during a computer hacking forensic investigation. She believes modifying this key is associated with the recent cyberattack on the company's servers. In order to confirm this, Janet needs to reference a timestamp embedded inside the registry key. What is the correct name of this timestamp?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 63
Single choice
Frank, a cloud administrator in his company, needs to take backup of the OS disks of two Azure VMs that store business-critical data. Which type of Azure blob storage can he use for this purpose?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 64
Single choice
The process of restarting a computer that is already turned on through the operating system is called?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 65
Single choice
What encryption technology is used on Blackberry devices Password Keeper?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 66
Single choice
Consider the scenario where a large multinational corporation suspects an internal security breach, with significant data possibly compromised.The corporate forensic team initiates the process of conducting a comprehensive forensic investigation following the search and seizureprotocols. During this process, they want to ensure they capture all the required information and minimize disruption to the company's ongoingbusiness operations. Which among the following activities should NOT be a part of their plan for this search and seizure operation?
-
A
Generating a comprehensive list of all potentially involved devices along with their specifications, status, and locations
-
B
Obtaining formal written consent from the company's owner before beginning the investigation process
-
C
Requesting a warrant for search and seizure detailing the exact locations and types of evidence expected to be found
-
D
Carrying out all search and seizure activities without seeking witness signatures for the activities performed
Reveal answer details
Close answer details
Question 67
Single choice
A mobile operating system is the operating system that operates a mobile device like a mobile phone, smartphone, PDA, etc. It determines the functions and features available on mobile devices such as keyboards, applications, email, text messaging, etc. Which of the following mobile operating systems is free and open source?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 68
Single choice
What will the following URL produce in an unpatched IIS Web Server? http://www.thetargetsite.com/scripts/..% co%af../..%co%af../windows/system32/cmd.exe?/c+dir+c:\
-
A
Directory listing of C: drive on the web server
-
B
Execute a buffer flow in the C: drive of the web server
-
C
Directory listing of the C:\windows\system32 folder on the web server
-
D
Insert a Trojan horse into the C: drive of the web server
Reveal answer details
Close answer details
Question 69
Single choice
During a forensic investigation, an attorney requested a forensic investigator to check if Dropbox was installed on the suspect's hard drive. The investigator finds traces of Dropbox artifacts in C:\Users\Admin \AppData\Roaming\, C:\Program Files (x86) and C:\Program Files directories. If the hypothesis is that the operating system installed is Windows 10, and Dropbox installation is confirmed by its artifacts in the mentioned directories, which assertion is the investigator most likely to make?
-
A
The Dropbox was installed on the suspect's machine using the open-source version of the installation package
-
B
The Dropbox application was most likely installed on the system running Windows 10
-
C
The Dropbox artifacts were manually moved to the mentioned directories on the suspect's hard drive
-
D
The Dropbox installation occurred using Windows 10's built-in installation manager
Reveal answer details
Close answer details
Question 70
Single choice
What does the 63.78.199.4(161) denotes in a Cisco router log? Mar 14 22:57:53.425 EST: %SEC-6-IPACCESSLOGP: list internet-inbound denied udp 66.56.16.77(1029)
-> 63.78.199.4(161), 1 packet
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 71
Single choice
An Employee is suspected of stealing proprietary information belonging to your company that he had no rights to possess. The information was stored on the Employees Computer that was protected with the NTFS Encrypted File System (EFS) and you had observed him copy the files to a floppy disk just before leaving work for the weekend. You detain the Employee before he leaves the building and recover the floppy disks and secure his computer. Will you be able to break the encryption so that you can verify that that the employee was in possession of the proprietary information?
-
A
EFS uses a 128-bit key that can't be cracked, so you will not be able to recover the information
-
B
The EFS Revoked Key Agent can be used on the Computer to recover the information
-
C
When the encrypted file was copied to the floppy disk, it was automatically unencrypted, so you can recover the information.
-
D
When the Encrypted file was copied to the floppy disk, the EFS private key was also copied to the floppy disk, so you can recover the information.
Reveal answer details
Close answer details
Question 72
Single choice
Which of the following Registry components include offsets to other cells as well as the LastWrite time for the key?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 73
Single choice
As a Computer Hacking Forensics Investigator, you have been tasked with examining a suspicious.E01 disk image file using The Sleuth Kit (TSK). You need to display the metadata structure of an inode but also want to show the addresses of its disk units. Which TSK command would best serve this purpose?
-
A
istat [-B num ] [-f fstype ] [-i imgtype] [-o imgoffset] [-b dev_sector_size] [-vV] [-z zone ] [-s seconds ] image [images] inode
-
B
img_stat [-i imgtype] [-b dev_sector_size] [-tvV] image [images]
-
C
fsstat [-f fstype ] [-i imgtype] [-o imgoffset] [-b dev_sector_size] [-tvV] image [images]
-
D
fls [-adDFIpruvV] [-m mnt ] [-z zone ] [-f fstype ] [-s seconds ] [-i imgtype ] [-o imgoffset ] [-b dev_sector_size] image [images] [ inode]
Reveal answer details
Close answer details
Question 74
Single choice
This organization maintains a database of hash signatures for known software
-
A
International Standards Organization
-
B
Institute of Electrical and Electronics Engineers
-
C
National Software Reference Library
-
D
American National standards Institute
Reveal answer details
Close answer details
Question 75
Single choice
An "idle" system is also referred to as what?
-
A
PC not connected to the Internet
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 76
Single choice
Heather, a computer forensics investigator, is assisting a group of investigators working on a large computer fraud case involving over 20 people. These 20 people, working in different offices, allegedly siphoned off money from many different client accounts. Heather responsibility is to find out how the accused people communicated between each other. She has searched their email and their computers and has not found any useful evidence. Heather then finds some possibly useful evidence under the desk of one of the accused. In an envelope she finds a piece of plastic with numerous holes cut out of it. Heather then finds the same exact piece of plastic with holes at many of the other accused peoples desks. Heather believes that the 20 people involved in the case were using a cipher to send secret messages in between each other. What type of cipher was used by the accused in this case?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 77
Single choice
An investigator enters the command sqlcmd -S WIN-CQQMK62867E -e -s"," -E as part of collecting the primary data file and logs from a database. What does the "WIN-CQQMK62867E" represent?
-
A
-
B
-
C
Operating system of the system
-
D
Network credentials of the database
Reveal answer details
Close answer details
Question 78
Single choice
Damaged portions of a disk on which no read/Write operation can be performed is known as ______________.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 79
Single choice
What is the first step that needs to be carried out to crack the password?
-
A
A word list is created using a dictionary generator program or dictionaries
-
B
The list of dictionary words is hashed or encrypted
-
C
The hashed wordlist is compared against the target hashed password, generally one word at a time
-
D
If it matches, that password has been cracked and the password cracker displays the unencrypted version of the password
Reveal answer details
Close answer details
Question 80
Single choice
Graphics Interchange Format (GIF) is a ____ RGB bitmap image format for images with up to 256 distinct colors per frame.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 81
Single choice
Preparing an image drive to copy files to is the first step in Linux forensics. For this purpose, what would the following command accomplish? dcfldd if=/dev/zero of=/dev/hda bs=4096 conv=noerror, sync
-
A
-
B
-
C
Fill the disk with 4096 zeros
-
D
Copy files from the master disk to the slave disk on the secondary IDE controller
Reveal answer details
Close answer details
Question 82
Single choice
A computer forensics investigator is inspecting the firewall logs for a large financial institution that has employees working 24 hours a day, 7 days a week.  What can the investigator infer from the screenshot seen below?
-
A
A smurf attack has been attempted
-
B
A denial of service has been attempted
-
C
Network intrusion has occurred
-
D
Buffer overflow attempt on the firewall.
Reveal answer details
Close answer details
Question 83
Single choice
Kimberly is studying to be an IT security analyst at a vocational school in her town. The school offers many different programming as well as networking languages. What networking protocol language should she learn that routers utilize?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 84
Single choice
Following an advanced persistent threat attack, a CHFI investigator is called in to acquire data from the compromised system. Given the wide range of potential data sources, the investigator needs to prioritize the order of data collection based on volatility. Which of the following would be the correct order to collect data in this scenario?
-
A
Archival media, physical configuration, network topology, disk or other storage media, temporary file systems, routing table, process table,kernel statistics, registers and processor cache
-
B
Archival media, disk or other storage media, temporary file systems, routing table, process table, and kernel statistics, registers andprocessor cache, physical configuration, and network topology
-
C
Registers and processor cache, routing table, process table, kernel statistics, temporary file systems, disk or other storage media, physicalconfiguration, and network topology, archival media
-
D
Physical configuration, network topology, archival media, disk or other storage media, temporary file systems, routing table, process table,kernel statistics, registers and processor cache
Reveal answer details
Close answer details
Question 85
Single choice
A Computer Hacking Forensics Investigator (CHFI) is working on a case involving an encrypted file from a user profile that was deleted. The investigator knows that the file was encrypted using the Encrypted File System (EFS) on a Windows operating system. The system is still bootable, but the original user profile is gone, and the system administrator has reset the account password. What would be the most suitable tool to recover this EFS-encrypted file?
-
A
Shredlt, a disk wiping utility tool
-
B
VeraCrypt, a widely used tool in anti-forensics encryption
-
C
AnalyzeMFT, a tool for examining MACE times in NTFS file systems
-
D
Advanced EFS Data Recovery, a tool for decrypting protected files
Reveal answer details
Close answer details
Question 86
Single choice
Which of the following should a computer forensics lab used for investigations have?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 87
Single choice
The disk in the disk drive rotates at high speed, and heads in the disk drive are used only to read data.
-
A
-
B
Reveal answer details
Close answer details
Question 88
Single choice
When using Windows acquisitions tools to acquire digital evidence, it is important to use a well-tested hardware write-blocking device to _________
-
A
Automate collection from image files
-
B
Avoiding copying data from the boot partition
-
C
Acquire data from the host-protected area on a disk
-
D
Prevent contamination to the evidence drive
Reveal answer details
Close answer details
Question 89
Single choice
Which part of Metasploit framework helps users to hide the data related to a previously deleted file or currently unused by the allocated file.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 90
Single choice
On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 91
Single choice
The Recycle Bin is located on the Windows desktop. When you delete an item from the hard disk, Windows sends that deleted item to the Recycle Bin and the icon changes to full from empty, but items deleted from removable media, such as a floppy disk or network drive, are not stored in the Recycle Bin. What is the size limit for Recycle Bin in Vista and later versions of the Windows?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 92
Single choice
A large multinational corporation suspects an internal breach of its data center and hires a forensic investigator. The investigator is required toconduct a search on the emails of an employee who is a US citizen, believed to be communicating classified information with a foreign entity. The forensic investigator, while respecting international laws and US privacy laws, should:
-
A
Utilize the Privacy Act of 1974 to access the individual's personal records without their written consent
-
B
Use the Foreign Intelligence Surveillance Act of 1978 (FISA) to get judicial authorization for electronic surveillance
-
C
Refer to the Protect America Act of 2007 to conduct surveillance without a speci c warrant on the employee's electronic communication
-
D
Apply the provisions under the Cybercrime Act 2001 of Australia to initiate electronic surveillance
Reveal answer details
Close answer details
Question 93
Single choice
How often must a company keep log files for them to be admissible in a court of law?
-
A
All log files are admissible in court no matter their frequency
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 94
Single choice
What do you call the process of studying the changes that have taken place across a system or a machine after a series of actions or incidents?
-
A
Windows Services Monitoring
-
B
-
C
Start-up Programs Monitoring
-
D
Host integrity Monitoring
Reveal answer details
Close answer details
Question 95
Single choice
Which of the following acts as a network intrusion detection system as well as network intrusion prevention system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 96
Single choice
Which of the following statements is incorrect when preserving digital evidence?
-
A
Document the actions and changes that you observe in the monitor, computer, printer, or in other peripherals
-
B
Verily if the monitor is in on, off, or in sleep mode
-
C
Remove the power cable depending on the power state of the computer i.e., in on. off, or in sleep mode
-
D
Turn on the computer and extract Windows event viewer log files
Reveal answer details
Close answer details
Question 97
Single choice
The status of the network interface cards (NICs) connected to a system gives information about whether the system is connected to a wireless access point and what IP address is being used. Which command displays the network configuration of the NICs on the system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 98
Single choice
Depending upon the jurisdictional areas, different laws apply to different incidents. Which of the following law is related to fraud and related activity in connection with computers?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 99
Single choice
Which of the following Steganography techniques allows you to encode information that ensures creation of cover for secret communication?
-
A
-
B
Transform domain techniques
-
C
Cover generation techniques
-
D
Spread spectrum techniques
Reveal answer details
Close answer details
Question 100
Single choice
What information do you need to recover when searching a victim's computer for a crime committed with specific e-mail message?
-
A
Internet service provider information
-
B
-
C
-
D
Reveal answer details
Close answer details
|