wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Pre-test Training IR and Hands On Lab - Telkomsigma

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?

a)

Process Explore

b)

nbtstat

c)

netstat

d)

Autopsy

2.

Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?

a)

Swap file

b)

Slack space

c)

Process memory

d)

Event logs

3.

Drake is an incident handler in Dark CLoud Inc. He is intended to perform log analysis in order to detect traces of malicious activities within the network infrastructure. Which of the following tools Drake must employ in order to view logs in real time and identify malware propagation within the network?

a)

HULK

b)

LOIC

c)

Hydra

d)

Splunk

4.

Eric who is an incident responder is working on developing incident-handling plans and procedures. As part of this process, he is performing analysis on the organizational network to generate a report and to develop policies based on the acquired results.

Which of the following tools will help him in analyzing network and its related traffic?

a)

Burp Suite

b)

Whois

c)

Wireshark

d)

FaceNiff

5.

Which of the following malware detection technique is employed in intrusion analysis to identify the transfer of any unwanted traffic to malicious or unknown external entities?

a)

Covert Malware Beaconing

b)

SSDT Patching

c)

Kernel Filter Drivers

d)

Covert C&C Communication

6.

Which of the following terms refers to an organization’s ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?

a)

Data analysis

b)

Risk assessment

c)

Threat assessment

d)

Forensic readiness

7.

Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during incident response process. She was also told that the system backup can also be used for further investigation of the incident.

In which of the following stages of the incident handling and response (IH&R) process Alice has to take the complete backup of the infected system?

a)

Containment

b)

Eradication

c)

Incident recording

d)

Incident triage

8.

Which of the following techniques prevent or mislead incident-handling process and may also affect the collection, preservation, and identification phases of the forensic investigation process?

a)

Scanning

b)

Footprinting

c)

Anti-forensics

d)

Enumeration

9.

In which of the following stages of incident handling does classification and prioritization of incidents take place?

a)

Incident Containment

b)

Incident Triage

c)

Incident Recording and Assignment

d)

Post-Incident Activities

10.

Alex is an incident handler for Tech-o-Tech Inc. and he is intended to identify any possible insider threats in his organization.

Which of the following insider threat detection techniques can be used by him to detect insider threats based on the behavior of a doubtful employee both individually and in a group?

a)

Profiling

b)

Physical detection

c)

Mole detection

d)

Behavioral analysis