
CO2517 Digital Evidence 2023 Part 1
Authored by Christopher Finnigan
Computers
University

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
11 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of these is NOT part of the IR Preparation stage?
Determining
Preparing documentation
IR policies
Retention of evidence
Answer explanation
Retention of evidence − evidence collected typically has to be stored for a certain period and part of the post-incident activities.
2.
DROPDOWN QUESTION
1 min • 1 pt
An event is (a) in a computer system.
Whilst a incident is (b) for organisation or individuals.
3.
REORDER QUESTION
1 min • 1 pt
Reorder these stages of the Incident Response Lifecycle
Detection & Analysis
Post-Incident Activity
Preparation
Containment, Eradication& Recovery
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of these are NOT in the IR Preparation
Segmentation
Risk analysis
Determining how Indicents are reported.
Preparing an IR team
Answer explanation
Segmentation – more advanced than isolation by using a honeynet and allow the attacker to continue to receive filtered output to deceive him/her into thinking the attack is progressing successfully. This part of the Incident Containment phase.
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of these is NOT part of the IR Detection & Analysis stage?
Recordings
Recovery Procedures
Incident Indicator Validation
Incident Indicator Definitions
Answer explanation
Definition of what would confirm the incident would be in the preparation phase.
6.
DRAG AND DROP QUESTION
1 min • 1 pt
(a) could use a honeynet to allow attack to receive filled output and part of th (b) phase.
Answer explanation
Segmentation – more advanced than isolation by using a honeynet and allow the attacker to continue to receive filtered output to deceive him/her into thinking the attack is progressing successfully.
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of these activities are NOT part of the Post-Incident phase.
retention of evidence
risk assessment
collected metrics
lessons learned
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?