Search Header Logo

CO2517 Digital Evidence 2023 Part 1

Authored by Christopher Finnigan

Computers

University

CO2517 Digital Evidence 2023 Part 1
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

11 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these is NOT part of the IR Preparation stage?

Determining

Preparing documentation

IR policies

Retention of evidence

Answer explanation

Retention of evidence − evidence collected typically has to be stored for a certain period and part of the post-incident activities.

2.

DROPDOWN QUESTION

1 min • 1 pt

An event is ​ (a)   in a computer system.

Whilst a incident is ​ ​ (b)   for organisation or individuals.

an observable occurence
an negatively event with a potential impact

3.

REORDER QUESTION

1 min • 1 pt

Reorder these stages of the Incident Response Lifecycle

Detection & Analysis

Post-Incident Activity

Preparation

Containment, Eradication& Recovery

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these are NOT in the IR Preparation

Segmentation

Risk analysis

Determining how Indicents are reported.

Preparing an IR team

Answer explanation

Segmentation – more advanced than isolation by using a honeynet and allow the attacker to continue to receive filtered output to deceive him/her into thinking the attack is progressing successfully. This part of the Incident Containment phase.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these is NOT part of the IR Detection & Analysis stage?

Recordings

Recovery Procedures

Incident Indicator Validation

Incident Indicator Definitions

Answer explanation

Definition of what would confirm the incident would be in the preparation phase.

6.

DRAG AND DROP QUESTION

1 min • 1 pt

​ (a)   could use a honeynet to allow attack to receive filled output and part of th (b)   phase.

Segmentation
Containment
Analysis
Preparation
IR Planning
IR

Answer explanation

Segmentation – more advanced than isolation by using a honeynet and allow the attacker to continue to receive filtered output to deceive him/her into thinking the attack is progressing successfully.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these activities are NOT part of the Post-Incident phase.

retention of evidence

risk assessment

collected metrics

lessons learned

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?