Font size
WorksheetsEverything Computer Forensics
Total questions: 90
Worksheet time: 15mins
Windows 95 was the first OS to support this older file system?
FAT32
NTFS
ReFS
This is about obfuscating a message so that it cannot be read?
Cryptography
Steganography
Scientology
This calculation is used to calculate single loss expectency?
SLE
ALE
NIST
_______________ memory analysis is a live-system forensic technique in which you collect a memory dump and perform analysis in an isolated environment?
Static
Volatile
System
If the computer is turned on when you arrive, what does the Secret Service recommend you do?
Begin investigation immediately
Shut the computer down according to the recommended Secret Service procedure
Transport the computer with power on
Which of the following might contain data that was live in memory and not stored on the hard-drive?
Swap File
Registry Hive
Log File
What is the most important reason that you not touch the actual original evidence any more than you have to?
Each time you touch digital data, there is some chance of altering it.
You might be accused of planting evidence
You might accidentally decrypt files
The MD5 message-digest algorithm is used to _____.
Hash a disk to verify that a disk is not altered when you examine it
Wipe magnetic media before recycling it
Make directories on an evidence drive
What Linux command helps you delete or remove a file?
rm
cd
del
Which below is a technique for file system repair that involves recovering data from a damaged partition with limited knowledge of the file system?
Zero-knowledge analysis
Point-Blank analysis
low-level analysis
Spyware is legal?
True
False
Business Continuity Plan development depends most on:
the Business Impact Analysis (BIA)
scope and plan initiation
directives from senior management
What is the primary reason to take cyberstalking seriously?
It can be a prelude to real-world violence.
It can damage your system
In can be annoying and distracting
Encrypting files/folders would be an example of:
cryptography
steganography
scientology
Which of the following drives would be least susceptible to damage when dropped?
SCSI
SSD
SATA
Which log file contains failed user logins?
/var/log/kern.log
/var/log/faillog
/var/log/lpr.log
What is the essence of the Daubert standard?
The only tools or techniques that have been accepted by the scientific community are admissible in trial
Only experts can testify at a trial
The Chain of Custody can be broken in criminal investigations
What file system does Windows 10 use?
FAT32
NTFS
HPFS
RAID-____ is known as a MIRROR and is essentially two-hard drives with one being an identical copy of the other.
0
1
5
What Linux command can be used to wipe a target drive?
Del
nc
dd
Evidence need not be locked if it is at a police station.
True
False
Which backup will backup all changes?
Full
Differential
Incremental
In Windows 10, the swap file ends with what extension?
.sys
.swap
.dir
Many forensic tools and software have the option to do a forensic wipe for you. This Linux command can also do that:
.del
dd
format_wipe
Which of the following is the Linux equivalent of a shortcut?
Hard Link
Symbolic Link
Partial Link
Once a incident has been detected, you should then:
Eradicate it
Contain it
Detect it a second time
Which of the following focuses on keeping the organization functioning as well as possible until a full recovery can be made?
Business Continuity Plan
Business Recovery Plan
Disaster Recovery Plan
ReFS is the newest file system for Windows. What has been the popular file system used by Windows for the last 10-20 years?
HFS+
FAT32
NTFS
What file system does MAC OS use?
EXT3
HFS+
NTFS
What type of attack results from an attacker sending specially crafted packets to a web server that cause it to crash?
DoS
Malware
MITM
Once an intrusion into your organizations information system has been detected, which of the following actions should be performed first?
Eliminate all means of intruder access
Contain the intrusion
Determine to what extent systems and data are compromised
Which is a common method for scoring system vulnerabilities?
SLE
CVSS
NIST
It is legal for employers to monitor work computers?
True
False
Which of the following focuses on sustaining an organizations business functions during and after a disruption?
Business Continuity Plan
Business Recovery Plan
Disaster Recovery Plan
Damage to how data is stored, such as file system corruption, is known as:
Physical Damage
Logical Damage
Stricking Damage
Your roommate can give consent to search your computer.
True
False
Maybe
Which backup will backup all changes since last full backup?
Full
Differential
Incremental
What is the most commonly used hashing algorithm?
SHA1
MD5
Whirlpool
Which of the following is an asymmetric cryptography algorithm invented by 3 mathematicians in the 1970s?
DES
AES
RSA
Deep Sound is a tool that allows you to:
encrypt files, hard-drives and volumes
hide files in mp3, wav, cda and other file formats
wipe a hard-drive completely clean
Logic bombs are often perpetrated by:
Terrorists
Hackers
Disgruntled employees
Using "science and technology to investigate and establish facts in criminal or civil courts of law" is called:
Forensics
Accounting
Hardening
Why can you undelete files in Windows 7?
Nothing is deleted; it is just removed from MFT
Fragments might exist; even though the file is deleted
You cannot
What Windows Log is most-likely the most important log from a forensics point of view?
Application log
System log
Security log
The art and science of writing hidden messages is known as:
cryptography
steganography
scientology
Which of the following is an asymmetric cryptography algorithm invented by 3 mathematicians in the 1970s?
NSA
RSA
AES
What type of encryption uses a different key to encrypt the message than it uses to decrypt the message?
Asymmetric
Symmetric
Private-Key
Where would you seek evidence that ophcrack had been used on a Windows Server 2008 machine?
In the logs of the server; look for the reboot of the system
In the logs of the server; look for the loading of a CD
in the firewall logs
When cataloging digital evidence, the primary goal is to do what?
Keep evidence in one location and not allow it to be removed from premises
Preserve evidence integrity
Keep the computer from being turned off
_____________ is commonly used name for a command-line utility that provides disk partitiioning functions in an operating system?
format
fdisk
parted
In a computer forensics investigation, describe the route that evidence takes from the time you find it until the case is closed or goes to court.
Policy of Journey
Chain of custody
Least Principle
Why should you note all cable connections for a computer you want to seize as evidence?
It’s just a standard
To know what peripheral devices were there
in case other devices were connected
When a Windows system books, the BIOS helps perform a:
BIOS start
POST
MITM
_________________________is a process used in computer forensics to extract data from a drive without the assistance of the file system; perhaps because the file has become corrupted?
file extraction
file carving
file restoration
Which backup will backup all change since last backup of any type”
Full
Differential
Incremental
What Linux command lists the contents of the current directory?
ls
dir
mkdir
Which of the following crimes is most likely to leave email evidence?
Cyberstalking
DoS
Fraud
This is an attempt to trick a victim into giving up personal information?
Trust
Phishing
Ransomware
RAID-____ combines three or more disks in a way that protects data against the loss of any one disk.
0
1
5
What is the most commonly used file system with Linux?
NTFS
Ext
ReFS
The use of analytical and investigative techniques to identify, collect, examine and preserve evidence is called:
Computer Forensics
Network Accounting
System Oversight
This is the primary standard for Contingency Planning Guide for Information Technology System?
ISO 27001
NIST 800-34
NFPA 1600
What is the purpose of hashing a copy of a suspect drive?
To make it secure
To remove viruses
To check for changes
In steganography, the _________________ is the data to be covertly communicated. In other words, it is the message you want to hide.
Payload
Carrier
Signal
What is the starting point for investigating denial of service attacks?
Firewall Logs
System Logs
Tracing the Packets
What kind of attack results from an attacker sending specially crafted packets to a web server to cause it to crash?
MITM Attack
DoS Attack
Cross-over Attack
This holds passwords with precalculated hashses of all password?
Rainbow Table
System Table
Hash Table
It takes _____ occurrence(s) of overextending yourself during testimony to ruin your reputation.
only one
several
at least two
How many HIVES are in the Windows Registry?
1
5
11
What assesses potential loss that could be caused by a disaster?
Business Assessment (BA)
Business Impact Analysis (BIA)
Business Continuity Plan (BCP)
What Linux command can be used to create a hash?
SHA
MD5sum
MD5
When investigating a virus, what is the first step?
Check firewall logs
Document the Virus
Trace the origin of Virus
What do you call a list of people who have had physical possession of the evidence?
Affidavit
Chain of custody
Evidence Team List
Hiding messages inside another medium is referred to as:
cryptography
steganography
cryptology
Which port below is associated with HTTPS?
25
443
3389
Which type of attack involves an attackers sending a large amount of ICMP packets to a target in hopes to overwhelm it?
Ping Flood (DDos)
Teardrop Attack
Spoof Flood
The synchronization bits in the TCP header can yield important information. Which below is a flag use to Reset a connection?
URG
ACK
RST
The Private Class B IP Range is:
150 - 160.x.x.x
172.16.0.0 - 172.31.255.255
Anything 170.x.x.x through 171.x.x.x
The synchronization bits in the TCP header can yeild important information. Which flag generally indicates the communication is ended?
URG
FIN
RST
Which port below is associated with DNS?
25
53
69
What TYPE of firewall is most likely to prevent SYN Floods, where an attacker sends unlimited SYNchronize requests to a host system?
Packet Filtering
Stateful Packet Inspection
Dynamic
When using Volatility, this command can examine the registry and is probably the one most useful in examining DLL injection?
printkey
volatilescan
onescan
Which malware below is software that appears to have some legitimate purpose, but when executied a second payload of malware is delivered instead?
Logic Bomb
Worm
Trojan Horse
This command is very command and is used to list details of all services that were in memory when a memory dump is taken?
svcscan
servscan
sfcscan
Which GUI program has a graphical user interface for Volatility and includes a Volatilty Workbench?
DumpFall.exe
OSForensics
ProDiscover-Gold
This table is a data structure that maps virtual addresses to physical addresses?
Heap
Page
Stack
The _____________ is memory that programs can allocate as needed; it is not the organized automatically allocated memory area?
stack
MDR
Heap
Which cloud technology applies to renting/using an entire network infrastructure that is virtulatized online?
IaaS
PaaS
SaaS
Which cloud technology applies to the ability to access software as a service on demand through the cloud?
IaaS
PaaS
SaaS
Which cloud technology applies to providing individual operating systems as a service so they can create programs and develop code?
IaaS
PaaS
SaaS
