Font size
WorksheetsCNET151 Chapt 14 - Introduction to Forensics
Total questions: 15
Worksheet time: 8mins
Frequently, the first responder to a computer crime is __________.
The network administrator
A law enforcement officer
The news media
A private investigator
If you fail to handle evidence properly __________.
You may damage the hard drive
It may be unusable in court
Law enforcement may not look at it
None of the above
You may use Linux to make a __________ of the hard drive.
Bootable copy
Screenshot
New version
Forensically valid copy
Use the Linux __________ command-line command to wipe the target drive in a forensics examination.
cc
dd
nc
md5sum
Use the Linux __________ command-line command to back up your hard drive if you want to create a hash.
cc
dd
nd
md5sum
Documentation of every person who had access to evidence, how they interacted with it, and where it was stored is called the __________.
Forensic trail
Chain of custody
Audit trail
Inspection report
Usually, the first thing you do to a computer to prevent further tampering is to __________.
Make a backup
Make a copy
Take it offline
Lock it in a secure room
__________ can include logs, portable storage devices, emails, tablets, and cell phones.
Computer evidence
Ancillary hardware
Network devices
The Windows Registry
Windows stores information on web addresses, search queries, and recently opened files in a file called__________.
internet.txt
index.dat
default.dat
explore.exe
In Windows, the log that stores events from a single application or component rather than events that might have a systemwide impact is the __________ log.
Application
System
ForwardedEvents
Applications and Services
In Windows, the log that contains events collected from remote computers is the __________ log.
Application
System
ForwardedEvents
Applications and Services
The Linux log file that contains activity related to the web server is __________.
/var/log/kern.log
/var/log/apache2/*
/var/log/lpr.log
/var/log/apport.log
The Linux log file that can reveal attempts to compromise the system or the presence of a virus or spyware is __________.
/var/log/kern.log
/var/log/apache2/*
/var/log/lpr.log
/var/log/apport.log
__________ is a free tool that can be used to recover Windows files.
SearchIt
DiskDigger
FileRecover
FTK Imager
Which cell phone state identified by the U.S. National Institute of Standards is a dormant mode that conserves battery life while maintaining user data and performing other background functions?
Quiescent
Active
Nascent/factory default
Semi-active
