CO2517 Digital Evidence 2023 Part 1

CO2517 Digital Evidence 2023 Part 1

University

11 Qs

quiz-placeholder

Similar activities

Chapter 11: Disaster Recovery and Contingency Planning

Chapter 11: Disaster Recovery and Contingency Planning

University

10 Qs

Tanggap Insiden Kamsiber 14 Maret 2022

Tanggap Insiden Kamsiber 14 Maret 2022

University

12 Qs

CNET251 - Ch 7 Treating Risk

CNET251 - Ch 7 Treating Risk

University

10 Qs

Problem Management ITIL4

Problem Management ITIL4

University

16 Qs

AI dan Big Data

AI dan Big Data

University

15 Qs

Module 4

Module 4

7th Grade - University

15 Qs

IR 4.0 Quiz

IR 4.0 Quiz

University

13 Qs

Computer Architecture Unit 3

Computer Architecture Unit 3

University

15 Qs

CO2517 Digital Evidence 2023 Part 1

CO2517 Digital Evidence 2023 Part 1

Assessment

Quiz

Computers

University

Hard

Created by

Christopher Finnigan

FREE Resource

11 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these is NOT part of the IR Preparation stage?

Determining

Preparing documentation

IR policies

Retention of evidence

Answer explanation

Retention of evidence − evidence collected typically has to be stored for a certain period and part of the post-incident activities.

2.

DROPDOWN QUESTION

1 min • 1 pt

An event is ​ (a)   in a computer system.

Whilst a incident is ​ ​ (b)   for organisation or individuals.

an observable occurence
an negatively event with a potential impact

3.

REORDER QUESTION

1 min • 1 pt

Reorder these stages of the Incident Response Lifecycle

Containment, Eradication& Recovery

Preparation

Post-Incident Activity

Detection & Analysis

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these are NOT in the IR Preparation

Segmentation

Risk analysis

Determining how Indicents are reported.

Preparing an IR team

Answer explanation

Segmentation – more advanced than isolation by using a honeynet and allow the attacker to continue to receive filtered output to deceive him/her into thinking the attack is progressing successfully. This part of the Incident Containment phase.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these is NOT part of the IR Detection & Analysis stage?

Recordings

Recovery Procedures

Incident Indicator Validation

Incident Indicator Definitions

Answer explanation

Definition of what would confirm the incident would be in the preparation phase.

6.

DRAG AND DROP QUESTION

1 min • 1 pt

​ (a)   could use a honeynet to allow attack to receive filled output and part of th (b)   phase.

Segmentation
Containment
Analysis
Preparation
IR Planning
IR

Answer explanation

Segmentation – more advanced than isolation by using a honeynet and allow the attacker to continue to receive filtered output to deceive him/her into thinking the attack is progressing successfully.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of these activities are NOT part of the Post-Incident phase.

retention of evidence

risk assessment

collected metrics

lessons learned

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?