wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CHFI new part 2

Total questions: 120

Worksheet time: 3600secs

Name
Class
Date
1.
What technique is used by JPEGs for compression?
a)
ZIP
b)
TCD
c)
DCT
d)
TIFF-8
2.
When using an iPod and the host computer is running Windows, what file system will be used?
a)
iPod+
b)
HFS
c)
FAT16
d)
FAT32
3.
Smith is an IT technician that has been appointed to his company's network vulnerability assessment team. He is the only IT employee on the team. The other team members include employees from Accounting, Management, Shipping, and Marketing. Smith and the team members are having their first meeting to discuss how they will proceed. What is the first step they should do to create the network vulnerability assessment plan?
a)
Their first step is to make a hypothesis of what their final findings will be.
b)
Their first step is to create an initial Executive report to show the management team.
c)
Their first step is to analyze the data they have currently gathered from the company or interviews.
d)
Their first step is the acquisition of required documents, reviewing of security policies and compliance.
4.
You have used a newly released forensic investigation tool, which doesn't meet the Daubert Test, during a case. The case has ended-up in court. What argument could the defense make to weaken your case?
a)
The tool hasn't been tested by the International Standards Organization (ISO)
b)
Only the local law enforcement should use the tool
c)
The total has not been reviewed and accepted by your peers
d)
You are not certified for using the tool
5.
You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?
a)
Packet filtering firewall
b)
Circuit-level proxy firewall
c)
Application-level proxy firewall
d)
Stateful firewall
6.
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive foot printing against their Web servers. What tool should you use?
a)
Ping sweep
b)
Nmap
c)
Netcraft
d)
Dig
7.
While looking through the IIS log file of a web server, you find the following entries: What is evident from this log file?
a)
Web bugs
b)
Cross site scripting
c)
Hidden fields
d)
SQL injection is possible
8.
Which of the following technique creates a replica of an evidence media?
a)
Data Extraction
b)
Backup
c)
Bit Stream Imaging
d)
Data Deduplication
9.
An investigator has extracted the device descriptor for a 1GB thumb drive that looks like: Disk&Ven_Best_Buy&Prod_Geek_Squad_U3&Rev_6.15. What does the “Geek_Squad” part represent?
a)
Product description
b)
Manufacturer Details
c)
Developer description
d)
Software or OS used
10.
When obtaining a warrant, it is important to:
a)
particularlydescribe the place to be searched and particularly describe the items to be seized
b)
generallydescribe the place to be searched and particularly describe the items to be seized
c)
generallydescribe the place to be searched and generally describe the items to be seized
d)
particularlydescribe the place to be searched and generally describe the items to be seized
11.
What is one method of bypassing a system BIOS password?
a)
Removing the processor
b)
Removing the CMOS battery
c)
Remove all the system memory
d)
Login to Windows and disable the BIOS password
12.
Identify the location of Recycle Bin on a Windows 7 machine that uses NTFS file system to store and retrieve files on the hard disk.
a)
Drive:\$Recycle.Bin
b)
DriveARECYCLER
c)
C:\RECYCLED
d)
DriveARECYCLED
13.
Analyze the hex representation of mysql-bin.000013 file in the screenshot below. Which of the following will be an inference from this analysis?
a)
A user with username bad_guy has logged into the WordPress web application
b)
A WordPress user has been created with the username anonymous_hacker
c)
An attacker with name anonymous_hacker has replaced a user bad_guy in the WordPress database
d)
A WordPress user has been created with the username bad_guy
14.
Which of the following standard represents a legal precedent set in 1993 by the Supreme Court of the United States regarding the admissibility of expert witnesses' testimony during federal legal proceedings?
a)
SWGDE & SWGIT
b)
IOCE
c)
Frye
d)
Daubert
15.
You have compromised a lower-level administrator account on an Active Directory network of a small company in Dallas, Texas. You discover Domain Controllers through enumeration. You connect to one of the Domain Controllers on port 389 using ldp.exe. What are you trying to accomplish here?
a)
Poison the DNS records with false records
b)
Enumerate MX and A records from DNS
c)
Establish a remote connection to the Domain Controller
d)
Enumerate domain user accounts and built-in groups
16.
Malware analysis can be conducted in various manners. An investigator gathers a suspicious executable file and uploads It to VirusTotal in order to confirm whether the file Is malicious, provide information about Its functionality, and provide Information that will allow to produce simple network signatures. What type of malware analysis was performed here?
a)
Static
b)
Volatile
c)
Dynamic
d)
Hybrid
17.
In the following directory listing: Which file should be used to restore archived email messages for someone using Microsoft Outlook?
a)
Outlook bak
b)
Outlook ost
c)
Outlook NK2
d)
Outlook pst
18.
Which of the following stages in a Linux boot process involve initialization of the system’s hardware?
a)
BIOS Stage
b)
Bootloader Stage
c)
BootROM Stage
d)
Kernel Stage
19.
Which of the following commands shows you the names of all open shared files on a server and the number of file locks on each file?
a)
Net config
b)
Net file
c)
Net share
d)
Net sessions
20.
A breach resulted from a malware attack that evaded detection and compromised the machine memory without installing any software or accessing the hard drive. What technique did the adversaries use to deliver the attack?
a)
Fileless
b)
Trojan
c)
JavaScript
d)
Spyware
21.
Which type of attack is possible when attackers know some credible information about the victim's password, such as the password length, algorithms involved, or the strings and characters used in its creation?
a)
Rule-Based Attack
b)
Brute-Forcing Attack
c)
Dictionary Attack
d)
Hybrid Password Guessing Attack
22.
What does the part of the log, “% SEC-6-IPACCESSLOGP”, extracted from a Cisco router represent? options buffers were available
a)
The system was not able to process the packet because there was not enough room for all of the desired IP header
b)
Immediate action required messages
c)
Some packet-matching logs were missed because the access list log messages were rate limited, or no access list log
d)
A packet matching the log criteria for the given access list has been detected (TCP or UDP)
23.
A(n) _____________________ is one that's performed by a computer program rather than the attacker manually performing the steps in the attack sequence.
a)
blackout attack
b)
automated attack
c)
distributed attack
d)
central processing attack
24.
Which layer of iOS architecture should a forensics investigator evaluate to analyze services such as Threading, File Access, Preferences, Networking and high-level features?
a)
Core Services
b)
Media services
c)
Cocoa Touch
d)
Core OS
25.
Which ISO Standard enables laboratories to demonstrate that they comply with quality assurance and provide valid results?
a)
ISO/IEC 16025
b)
ISO/IEC 18025
c)
ISO/IEC 19025
d)
ISO/IEC 17025
26.
In a FAT32 system, a 123 KB file will use how many sectors?
a)
34
b)
25
c)
11
d)
56
27.
Which program is the bootloader when Windows XP starts up?
a)
KERNEL.EXE
b)
NTLDR
c)
LOADER
d)
LILO
28.
An investigator has found certain details after analysis of a mobile device. What can reveal the manufacturer information?
a)
Equipment Identity Register (EIR)
b)
Electronic Serial Number (ESN)
c)
International mobile subscriber identity (IMSI)
d)
Integrated circuit card identifier (ICCID)
29.
Watson, a forensic investigator, is examining a copy of an ISO file stored in CDFS format. What type of evidence is this?
a)
Data from a CD copied using Windows
b)
Data from a CD copied using Mac-based system
c)
Data from a DVD copied using Windows system
d)
Data from a CD copied using Linux system
30.
Smith is an IT technician that has been appointed to his company's network vulnerability assessment team. He is the only IT employee on the team. The other team members include employees from Accounting, Management, Shipping, and Marketing. Smith and the team members are having their first meeting to discuss how they will proceed. What is the first step they should do to create the network vulnerability assessment plan?
a)
Their first step is to make a hypothesis of what their final findings will be.
b)
Their first step is to create an initial Executive report to show the management team.
c)
Their first step is to analyze the data they have currently gathered from the company or interviews.
d)
Their first step is the acquisition of required documents, reviewing of security policies and compliance.
31.
In forensics.______are used lo view stored or deleted data from both files and disk sectors.
a)
Hash algorithms
b)
SI EM tools
c)
Host interfaces
d)
Hex editors
32.
companyXYZ has asked you to assess the security of their perimeter email gateway. From your office in New York you craft a specially formatted email message and send it across the Internet to an employee of CompanyXYZ. The employee of CompanyXYZ is aware.
a)
Source code review
b)
Reviewing the firewalls configuration
c)
Data items and vulnerability scanning
d)
Interviewing employees and network engineers
33.
Which of the following Android libraries are used to render 2D (SGL) or 3D (OpenGL/ES) graphics content to the screen?
a)
OpenGL/ES and SGL
b)
Surface Manager
c)
Media framework
d)
WebKit
34.
What must an investigator do before disconnecting an iPod from any type of computer?
a)
Unmount the iPod
b)
Mount the iPod
c)
Disjoin the iPod
d)
Join the iPod
35.
Sectors are pie-shaped regions on a hard disk that store data. Which of the following parts of a hard disk do not contribute in determining the addresses of data?
a)
Sectors
b)
Interface
c)
Cylinder
d)
Heads
36.
SO/IEC 17025 is an accreditation for which of the following:
a)
CHFI issuing agency
b)
Encryption
c)
Forensics lab licensing
d)
Chain of custody
37.
Hard disk data addressing is a method of allotting addresses to each _______ of data on a hard disk.
a)
Physical block
b)
Operating system block
c)
Hard disk block
d)
Logical block
38.
What is the size value of a nibble?
a)
0.5 kilo byte
b)
0.5 bit
c)
0.5 byte
d)
2 bits
39.
Robert is a regional manager working in a reputed organization. One day, he suspected malware attack after unwanted programs started to popup after logging into his computer. The network administrator was called upon to trace out any intrusion on the computer and he/she finds that suspicious activity has taken place within Autostart locations. In this situation, which of the following tools is used by the network administrator to detect any intrusion on a system?
a)
Hex Editor
b)
Internet Evidence Finder
c)
Process Monitor
d)
Report Viewer
40.
If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?
a)
Keep the device powered on
b)
Turn off the device immediately
c)
Remove the battery immediately
d)
Remove any memory cards immediately
41.
Which network attack is described by the following statement? “At least five Russian major banks came under a continuous hacker attack, although online client services were not disrupted. The attack came from a wide-scale botnet involving at least 24,000 computers, located in 30 countries.”
a)
DDoS
b)
Sniffer Attack
c)
Buffer Overflow
d)
Man-in-the-Middle Attack
42.
Which of the following is a federal law enacted in the US to control the ways that financial institutions deal with the private information of individuals?
a)
SOX
b)
HIPAA 1996
c)
GLBA
d)
PCI DSS
43.
A section of your forensics lab houses several electrical and electronic equipment. Which type of fire extinguisher you must install in this area to contain any fire incident?
a)
Class B
b)
Class D
c)
Class C
d)
Class A
44.
Which of the following is a responsibility of the first responder?
a)
Determine the severity of the incident
b)
Collect as much information about the incident as possible
c)
Share the collected information to determine the root cause
d)
Document the findings
45.
The objective of this act was to protect consumers’ personal financial information held by financial institutions and their service providers.
a)
Gramm-Leach-Bliley Act
b)
Sarbanes-Oxley 2002
c)
California SB 1386
d)
HIPAA
46.
To reach a bank web site, the traffic from workstations must pass through a firewall. You have been asked to review the firewall configuration to ensure that workstations in network 10.10.10.0/24 can only reach the bank web site 10.20.20.1 using https. Which of the following firewall rules meets this requirement?
a)
if (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 443) then permit
b)
if (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 80 or 443) then permit
c)
if (source matches 10.10.10.0 and destination matches 10.20.20.1 and port matches 443) then permit
47.
How many sectors will a 125 KB file use in a FAT32 file system?
a)
32
b)
16
c)
256
d)
25
48.
Donald made an OS disk snapshot of a compromised Azure VM under a resource group being used by the affected company as a part of forensic analysis process. He then created a vhd file out of the snapshot and stored it in a file share and as a page blob as backup in a storage account under different region. What Is the next thing he should do as a security measure?
a)
Recommend changing the access policies followed by the company
b)
Delete the snapshot from the source resource group
c)
Delete the OS disk of the affected VM altogether
d)
Create another VM by using the snapshot
49.
What encryption technology is used on Blackberry devices Password Keeper?
a)
3DES
b)
AES
c)
Blowfish
d)
RC5
50.
William is examining a log entry that reads 192.168.0.1 - - [18/Jan/2020:12:42:29 +0000) "GET / HTTP/1.1" 200 1861. Which of the following logs does the log entry belong to?
a)
The combined log format of Apache access log
b)
The common log format of Apache access log
c)
Apache error log
d)
IIS log
51.
What will the following Linux command accomplish? dd if=/dev/mem of=/home/sam/mem.bin bs=1024
a)
Copy the master boot record to a file
b)
Copy the contents of the system folder to a file
c)
Copy the running memory to a file
d)
Copy the memory dump file to an image file
52.
You have completed a forensic investigation case. You would like to destroy the data contained in various disks at the forensics lab due to sensitivity of the case. How would you permanently erase the data on the hard disk?
a)
Throw the hard disk into the fire
b)
Run the powerful magnets over the hard disk
c)
Format the hard disk multiple times using a low level disk utility
d)
Overwrite the contents of the hard disk with Junk data
53.
Gary, a computer technician, is facing allegations of abusing children online by befriending them and sending them illicit adult images from his office computer. What type of investigation does this case require?
a)
Administrative Investigation
b)
Criminal Investigation
c)
Both Criminal and Administrative Investigation
d)
Civil Investigation
54.
Which part of the Windows Registry contains the user's password file?
a)
HKEY_LOCAL_MACHINE
b)
HKEY_CURRENT_CONFIGURATION
c)
HKEY_USER
d)
HKEY_CURRENT_USER
55.
Law enforcement officers are conducting a legal search for which a valid warrant was obtained. While conducting the search, officers observe an item of evidence for an unrelated crime that was not included in the warrant. The item was clearly visible to the officers and immediately identified as evidence. What is the term used to describe how this evidence is admissible?
a)
Plain view doctrine
b)
Corpus delicti
c)
Locard Exchange Principle
d)
Ex Parte Order
56.
Before performing a logical or physical search of a drive in Encase, what must be added to the program?
a)
File signatures
b)
Keywords
c)
Hash sets
d)
Bookmarks
57.
When searching through file headers for picture file formats, what should be searched to find a JPEG file in hexadecimal format?
a)
FF D8 FF E0 00 10
b)
FF FF FF FF FF FF
c)
FF 00 FF 00 FF 00
d)
EF 00 EF 00 EF 00
58.
Pagefile.sys is a virtual memory file used to expand the physical memory of a computer. Select the registry path for the page file: Management\PrefetchParameters
a)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
b)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\System Management
c)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Device Management
d)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory
59.
When setting up a wireless network with multiple access points, why is it important to set each access point on a different channel?
a)
Multiple access points can be set up on the same channel without any issues
b)
Avoid over-saturation of wireless signals
c)
So that the access points will work on different frequencies
d)
Avoid cross talk
60.
Which of the following does not describe the type of data density on a hard disk?
a)
Volume density
b)
Track density
c)
Linear or recording density
d)
Areal density
61.
Which of the following files store the MySQL database data permanently, including the data that had been deleted, helping the forensic investigator in examining the case and finding the culprit?
a)
mysql-bin
b)
mysql-log
c)
iblog
d)
ibdata1
62.
What is the name of the Standard Linux Command that is also available as windows application that can be used to create bit-stream images?
a)
mcopy
b)
image
c)
MD5
d)
dd
63.
What will the following URL produce in an unpatched IIS Web Server? http://www.thetargetsite.com/scripts/..% co%af../..%co%af../windows/system32/cmd.exe?/c+dir+c:\
a)
Directory listing of C: drive on the web server
b)
Insert a Trojan horse into the C: drive of the web server
c)
Execute a buffer flow in the C: drive of the web server
d)
Directory listing of the C:\windows\system32 folder on the web server
64.
To which phase of the Computer Forensics Investigation Process does the Planning and Budgeting of a Forensics Lab belong?
a)
Post-investigation Phase
b)
Reporting Phase
c)
Pre-investigation Phase
d)
Investigation Phase
65.
George is a senior security analyst working for a state agency in Florida. His state's congress just passed a bill mandating every state agency to undergo a security audit annually. After learning what will be required, George needs to implement an IDS as soon as possible before the first audit occurs. The state bill requires that an IDS with a "time-based induction machine" be used. What IDS feature must George implement to meet this requirement?
a)
Signature-based anomaly detection
b)
Pattern matching
c)
Real-time anomaly detection
d)
Statistical-based anomaly detection
66.
You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London. After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and passwords. What tool could you use to get this information?
a)
Airsnort
b)
Snort
c)
Ettercap
d)
RaidSniff
67.
Recently, an Internal web app that a government agency utilizes has become unresponsive, Betty, a network engineer for the government agency, has been tasked to determine the cause of the web application's unresponsiveness. Betty launches Wlreshark and begins capturing the traffic on the local network. While analyzing the results, Betty noticed that a syn flood attack was underway. How did Betty know a syn flood attack was occurring?
a)
Wireshark capture shows multiple ACK requests and SYN responses from single/multiple IP address(es)
b)
Wireshark capture does not show anything unusual and the issue is related to the web application
c)
Wireshark capture shows multiple SYN requests and RST responses from single/multiple IP address(es)
d)
Wireshark capture shows multiple SYN requests and ACK responses from single/multiple IP address(es)
68.
Amber, a black hat hacker, has embedded a malware into a small enticing advertisement and posted it on a popular ad- network that displays across various websites. What is she doing?
a)
Click-jacking
b)
Compromising a legitimate site
c)
Spearphishing
d)
Malvertising
69.
Which of the following statements is true regarding SMTP Server? Server Server
a)
SMTP Server breaks the recipient’s address into Recipient’s name and his/her designation before passing it to the DNS
b)
SMTP Server breaks the recipient's address into Recipient’s name and recipient’s address before passing it to the DNS
c)
SMTP Server breaks the recipient’s address into Recipient’s name and domain name before passing it to the DNS Server
d)
SMTP Server breaks the recipient’s address into Recipient’s name and his/her initial before passing it to the DNS Server
70.
You are working as an investigator for a corporation and you have just received instructions from your manager to assist in the collection of 15 hard drives that are part of an ongoing investigation. Your job is to complete the required evidence custody forms to properly document each piece of evidence as it is collected by other members of your team. Your manager instructs you to complete one multi-evidence form for the entire case and a single-evidence form for each hard drive. How will these forms be stored to help preserve the chain of custody of the case? drive in an approved secure container. forms should be placed in the report file.
a)
All forms should be placed in an approved secure container because they are now primary evidence in the case.
b)
The multi-evidence form should be placed in the report file and the single-evidence forms should be kept with each hard
c)
The multi-evidence form should be placed in an approved secure container with the hard drives and the single-evidence
d)
All forms should be placed in the report file because they are now primary evidence in the case.
71.
When a file is deleted by Windows Explorer or through the MS-DOS delete command, the operating system inserts _______________ in the first letter position of the filename in the FAT database.
a)
A Capital X
b)
A Blank Space
c)
The Underscore Symbol
d)
The lowercase Greek Letter Sigma (s)
72.
You are called by an author who is writing a book and he wants to know how long the copyright for his book will last after he has the book published?
a)
70 years
b)
the life of the author
c)
the life of the author plus 70 years
d)
copyrights last forever
73.
Where are files temporarily written in Unix when printing?
a)
/usr/spool
b)
/var/print
c)
/spool
d)
/var/spool
74.
What header field in the TCP/IP protocol stack involves the hacker exploit known as the Ping of Death?
a)
ICMP header field
b)
TCP header field
c)
IP header field
d)
UDP header field
75.
This is a statement, other than one made by the declarant while testifying at the trial or hearing, offered in evidence to prove the truth of the matter asserted. Which among the following is suitable for the above statement?
a)
Testimony by the accused
b)
Limited admissibility
c)
Hearsay rule
d)
Rule 1001
76.
What is the name of the first reserved sector in File allocation table?
a)
Volume Boot Record
b)
Partition Boot Sector
c)
Master Boot Record
d)
BIOS Parameter Block
77.
In General, __________________ Involves the investigation of data that can be retrieved from the hard disk or other disks of a computer by applying scientific methods to retrieve the data.
a)
Network Forensics
b)
Data Recovery
c)
Disaster Recovery
d)
Computer Forensics
78.
______allows a forensic investigator to identify the missing links during investigation.
a)
Evidence preservation
b)
Chain of custody
c)
Evidence reconstruction
d)
Exhibit numbering
79.
Paul is a computer forensics investigator working for Tyler & Company Consultants. Paul has been called upon to help investigate a computer hacking ring broken up by the local police. Paul begins to inventory the PCs found in the hackers hideout. Paul then comes across a PDA left by them that is attached to a number of different peripheral devices. What is the first step that Paul must take with the PDA to ensure the integrity of the investigation?
a)
Place PDA, including all devices, in an antistatic bag
b)
Unplug all connected devices
c)
Power off all devices if currently on
d)
Photograph and document the peripheral devices
80.
A state department site was recently attacked and all the servers had their disks erased. The incident response team sealed the area and commenced investigation. During evidence collection they came across a zip disks that did not have the standard labeling on it. The incident team ran the disk on an isolated system and found that the system disk was accidentally erased. They decided to call in the FBI for further investigation. Meanwhile, they short listed possible suspects including three summer interns. Where did the incident team go wrong?
a)
They examined the actual evidence on an unrelated system
b)
They attempted to implicate personnel without proof
c)
They tampered with evidence by using it
d)
They called in the FBI without correlating with the fingerprint data
81.
Which forensic investigating concept trails the whole incident from how the attack began to how the victim was affected?
a)
Point-to-point
b)
End-to-end
c)
Thorough
d)
Complete event analysis
82.
Paul's company is in the process of undergoing a complete security audit including logical and physical security testing. After all logical tests were performed; it is now time for the physical round to begin. None of the employees are made aware of this round of testing. The security-auditing firm sends in a technician dressed as an electrician. He waits outside in the lobby for some employees to get to work and follows behind them when they access the restricted areas. After entering the main office, he is able to get into the server room telling the IT manager that there is a problem with the outlets in that room. What type of attack has the technician performed?
a)
Tailgating
b)
Backtrapping
c)
Man trap attack
d)
Fuzzing
83.
From the following spam mail header, identify the host IP that sent this spam? From jie02@netvigator.com jie02@netvigator.com Tue Nov 27 17:27:11 2001 Received: from viruswall.ie.cuhk.edu.hk (viruswall [137.189.96.52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT) Received: from mydomain.com (pcd249020.netvigator.com [203.218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12.1/8.12.1) with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT) Message-Id: >200111270926.fAR9QXwZ018431@viruswall.ie.cuhk.edu.hk From: "china hotel web" To: "Shlam" Subject: SHANGHAI (HILTON HOTEL) PACKAGE Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0 X-Priority: 3 X-MSMailPriority: Normal Reply-To: "china hotel web"
a)
137.189.96.52
b)
8.12.1.0
c)
203.218.39.20
d)
203.218.39.50
84.
What does the 63.78.199.4(161) denotes in a Cisco router log? Mar 14 22:57:53.425 EST: %SEC-6-IPACCESSLOGP: list internet-inbound denied udp 66.56.16.77(1029) -> 63.78.199.4(161), 1 packet
a)
Destination IP address
b)
Source IP address
c)
Login IP address
d)
None of the above
85.
What do you call the process of studying the changes that have taken place across a system or a machine after a series of actions or incidents?
a)
Windows Services Monitoring
b)
System Baselining
c)
Start-up Programs Monitoring
d)
Host integrity Monitoring
86.
Data density of a disk drive is calculated by using_______
a)
Slack space, bit density, and slack density.
b)
Track space, bit area, and slack space.
c)
Track density, areal density, and slack density.
d)
Track density, areal density, and bit density.
87.
What does the command “C:\>wevtutil gl ” display?
a)
Configuration information of a specific Event Log
b)
Event logs are saved in .xml format
c)
Event log record structure
d)
List of available Event Logs
88.
Which of the following is NOT an anti-forensics technique?
a)
Data Deduplication
b)
Steganography
c)
Encryption
d)
Password Protection
89.
Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB file and found the source from where the mail originated and the name of the file that disappeared upon execution. Now, he wants to examine the MIME stream content. Which of the following files is he going to examine?
a)
PRIV.STM
b)
gwcheck.db
c)
PRIV.EDB
d)
PUB.EDB
90.
When carrying out a forensics investigation, why should you never delete a partition on a dynamic disk?
a)
All virtual memory will be deleted
b)
The wrong partition may be set to active
c)
This action can corrupt the disk
d)
The computer will be set in a constant reboot state
91.
A forensics investigator is searching the hard drive of a computer for files that were recently moved to the Recycle Bin. He searches for files in C:\RECYCLED using a command line tool but does not find anything. What is the reason for this?
a)
He should search in C:\Windows\System32\RECYCLED folder
b)
The Recycle Bin does not exist on the hard drive
c)
The files are hidden and he must use switch to view them
d)
Only FAT system contains RECYCLED folder and not NTFS
92.
A forensic examiner is examining a Windows system seized from a crime scene. During the examination of a suspect file, he discovered that the file is password protected. He tried guessing the password using the suspect’s available information but without any success. Which of the following tool can help the investigator to solve this issue?
a)
Cain & Abel
b)
Xplico
c)
Recuva
d)
Colasoft’s Capsa
93.
What method of copying should always be performed first before carrying out an investigation?
a)
Parity-bit copy
b)
Bit-stream copy
c)
MS-DOS disc copy
d)
System level copy
94.
Report writing is a crucial stage in the outcome of an investigation. Which information should not be included in the report section?
a)
Speculation or opinion as to the cause of the incident
b)
Purpose of the report
c)
Author of the report
d)
Incident summary
95.
You are an information security analyst at a large pharmaceutical company. While performing a routine review of audit logs, you have noticed a significant amount of egress traffic to various IP addresses on destination port 22 during off-peak hours. You researched some of the IP addresses and found that many of them are in Eastern Europe. What is the most likely cause of this traffic? malicious external entities
a)
Malicious software on internal system is downloading research data from partner 5FTP servers in Eastern Europe
b)
Internal systems are downloading automatic Windows updates
c)
Data is being exfiltrated by an advanced persistent threat (APT)
d)
The organization's primary internal DNS server has been compromised and is performing DNS zone transfers to
96.
What is the capacity of Recycle bin in a system running on Windows Vista?
a)
2.99GB
b)
3.99GB
c)
Unlimited
d)
10% of the partition space
97.
> NMAP -sn 192.168.11.200-215 The NMAP command above performs which of the following?
a)
A trace sweep
b)
A port scan
c)
A ping scan
d)
An operating system detect
98.
Ivanovich, a forensics investigator, is trying to extract complete information about running processes from a system. Where should he look apart from the RAM and virtual memory?
a)
Swap space
b)
Application data
c)
Files and documents
d)
Slack space
99.
%3cscript%3ealert(”XXXXXXXX”)%3c/script%3e is a script obtained from a Cross-Site Scripting attack. What type of encoding has the attacker employed?
a)
Double encoding
b)
Hex encoding
c)
Unicode
d)
Base64
100.
You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls? (Choose two.)
a)
162
b)
161
c)
163
d)
160
101.
The Recycle Bin exists as a metaphor for throwing files away, but it also allows a user to retrieve and restore files. Once the file is moved to the recycle bin, a record is added to the log file that exists in the Recycle Bin. Which of the following files contains records that correspond to each deleted file in the Recycle Bin?
a)
INFO2
b)
INFO1
c)
LOGINFO1
d)
LOGINFO2
102.
Which U.S. law sets the rules for sending emails for commercial purposes, establishes the minimum requirements for commercial messaging, gives the recipients of emails the right to ask the senders to stop emailing them, and spells out the penalties in case the above said rules are violated?
a)
NO-SPAM Act
b)
American: NAVSO P-5239-26 (RLL)
c)
CAN-SPAM Act
d)
American: DoD 5220.22-M
103.
Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
a)
bench warrant
b)
wire tap
c)
subpoena
d)
search warrant
104.
What does the acronym POST mean as it relates to a PC?
a)
Primary Operations Short Test
b)
PowerOn Self Test
c)
Pre Operational Situation Test
d)
Primary Operating System Test
105.
Harold wants to set up a firewall on his network but is not sure which one would be the most appropriate. He knows he needs to allow FTP traffic to one of the servers on his network, but he wants to only allow FTP-PUT. Which firewall would be most appropriate for Harold? needs?
a)
Circuit-level proxy firewall
b)
Packet filtering firewall
c)
Application-level proxy firewall
d)
Data link layer firewall
106.
You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorized. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saved. What should you examine next in this case?
a)
The registry
b)
The swap file
c)
The recycle bin
d)
The metadata
107.
What type of attack sends spoofed UDP packets (instead of ping packets) with a fake source address to the IP broadcast address of a large network?
a)
Fraggle
b)
Smurf scan
c)
SYN flood
d)
Teardrop
108.
Which of the following tool is used to locate IP addresses?
a)
SmartWhois
b)
Deep Log Analyzer
c)
Towelroot
d)
XRY LOGICAL
109.
Which part of Metasploit framework helps users to hide the data related to a previously deleted file or currently unused by the allocated file.
a)
Waffen FS
b)
RuneFS
c)
FragFS
d)
Slacker
110.
Which of the following statements is TRUE with respect to the Registry settings in the user start-up folder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\.
a)
All the values in this subkey run when specific user logs on, as this setting is user-specific
b)
The string specified in the value run executes when user logs on
c)
All the values in this key are executed at system start-up
d)
All values in this subkey run when specific user logs on and then the values are deleted
111.
An investigator is analyzing a checkpoint firewall log and comes across symbols. What type of log is he looking at?
a)
Security event was monitored but not stopped
b)
Malicious URL detected
c)
An email marked as potential spam
d)
Connection rejected
112.
Self-Monitoring, Analysis, and Reporting Technology (SMART) is built into the hard drives to monitor and report system activity. Which of the following is included in the report generated by SMART?
a)
Power Off time
b)
Logs of high temperatures the drive has reached
c)
All the states (running and discontinued) associated with the OS
d)
List of running processes
113.
What hashing method is used to password protect Blackberry devices?
a)
AES
b)
RC5
c)
MD5
d)
SHA-1
114.
Which of the following is NOT a graphics file?
a)
Picture1.tga
b)
Picture2.bmp
c)
Picture3.nfo
d)
Picture4.psd
115.
How often must a company keep log files for them to be admissible in a court of law?
a)
All log files are admissible in court no matter their frequency
b)
Weekly
c)
Monthly
d)
Continuously
116.
What is the purpose of using Obfuscator in malware?
a)
Execute malicious code in the system
b)
Avoid encryption while passing through a VPN
c)
Avoid detection by security mechanisms
d)
Propagate malware to other connected devices
117.
You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London. After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and passwords. What tool could you use to get this information?
a)
Airsnort
b)
Snort
c)
Ettercap
d)
RaidSniff
118.
Which cloud model allows an investigator to acquire the instance of a virtual machine and initiate the forensics examination process?
a)
PaaS model
b)
IaaS model
c)
SaaS model
d)
SecaaS model
119.
In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact ISP and request that they provide you assistance with your investigation. What assistance can the ISP provide? and therefore cannot assist you without a warrant
a)
The ISP can investigate anyone using their service and can provide you with assistance
b)
The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers
c)
The ISP can't conduct any type of investigations on anyone and therefore can't assist you
d)
ISP's never maintain log files so they would be of no use to your investigation
120.
Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
a)
Mime-Version header
b)
Content-Type header
c)
Content-Transfer-Encoding header
d)
Errors-To header