WorksheetsPre-test Training IR and Hands On Lab - Telkomsigma
Total questions: 10
Worksheet time: 5mins
Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?
Process Explore
nbtstat
netstat
Autopsy
Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?
Swap file
Slack space
Process memory
Event logs
Drake is an incident handler in Dark CLoud Inc. He is intended to perform log analysis in order to detect traces of malicious activities within the network infrastructure. Which of the following tools Drake must employ in order to view logs in real time and identify malware propagation within the network?
HULK
LOIC
Hydra
Splunk
Eric who is an incident responder is working on developing incident-handling plans and procedures. As part of this process, he is performing analysis on the organizational network to generate a report and to develop policies based on the acquired results.
Which of the following tools will help him in analyzing network and its related traffic?
Burp Suite
Whois
Wireshark
FaceNiff
Which of the following malware detection technique is employed in intrusion analysis to identify the transfer of any unwanted traffic to malicious or unknown external entities?
Covert Malware Beaconing
SSDT Patching
Kernel Filter Drivers
Covert C&C Communication
Which of the following terms refers to an organization’s ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?
Data analysis
Risk assessment
Threat assessment
Forensic readiness
Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during incident response process. She was also told that the system backup can also be used for further investigation of the incident.
In which of the following stages of the incident handling and response (IH&R) process Alice has to take the complete backup of the infected system?
Containment
Eradication
Incident recording
Incident triage
Which of the following techniques prevent or mislead incident-handling process and may also affect the collection, preservation, and identification phases of the forensic investigation process?
Scanning
Footprinting
Anti-forensics
Enumeration
In which of the following stages of incident handling does classification and prioritization of incidents take place?
Incident Containment
Incident Triage
Incident Recording and Assignment
Post-Incident Activities
Alex is an incident handler for Tech-o-Tech Inc. and he is intended to identify any possible insider threats in his organization.
Which of the following insider threat detection techniques can be used by him to detect insider threats based on the behavior of a doubtful employee both individually and in a group?
Profiling
Physical detection
Mole detection
Behavioral analysis
