NEW
Font size
WorksheetsCS211 Quiz 03
Total questions: 15
Worksheet time: 15mins
Which of the following attacks best describe Bluesnarfing?
Denial of service via oversized L2CAP packets
Unauthorized extraction of SMS, contacts, or emails from a Bluetooth device
Sending anonymous messages to nearby Bluetooth devices
Exploiting OBEX protocol vulnerabilities
In Incident Response, the Eradication phase involves:
Removing malware/root cause from systems
Isolating affected systems to prevent spread
Restoring operations and monitoring
Reviewing lessons learned
Which of the following BEST defines Data Resilience?
Ability to detect malware in real-time
Ability to recover quickly from data loss or disruption
Ability to sanitize data using multiple passes
Ability to encrypt and decrypt sensitive files
Which of the following correctly distinguishes a data breach from a data leak?
Breach is intentional attack; leak is accidental exposure
Breach occurs from weak passwords; leak occurs from malware
Breach is only internal; leak is always external
Breach requires encryption bypass; leak does not
Data Masking is MOST useful in which scenario?
Encrypting stored passwords in a database
Obscuring customer credit card numbers in a CRM system
Destroying outdated business records
Creating incremental backup files
Which of the following backup methods is fastest to perform but slowest to restore?
Full backup
Incremental backup
Differential backup
Snapshot backup
Which of the following is part of the Containment phase of Incident Response?
Restoring system from clean backups
Disconnecting compromised hosts from the network
Conducting a lessons-learned meeting
Updating security patches
The Security Kernel's Reference Monitor must satisfy which conditions?
Verifiable, Tamper-proof, Always invoked
Decentralized, Flexible, Discretionary
Simple, Transparent, User-controlled
Large, Complex, Privilege-based
Which of the following OS hardening measures is specific to Windows?
AppLocker policies
SELinux
AuditD logging
Gatekeeper
Address Space Layout Randomization (ASLR) improves security by:
Randomizing the location of processes in memory
Encrypting the system call interface
Preventing network sniffing attacks
Blocking malicious bootloaders
During Dead Acquisition, which step ensures admissibility of evidence in court?
Capturing live network packets
Creating a bit-by-bit forensic image
Disconnecting power without warning
Editing log files to remove noise
Which forensic tool is primarily used for memory analysis?
EnCase
Autopsy
Volatility
FTK
The Chain of Custody is MOST important because it:
Ensures that data was encrypted during storage
Maintains evidence integrity for legal admissibility
Speeds up forensic imaging of hard drives
Ensures all backup copies are tested
In the context of operating system defense, which scenario demonstrates a failure of integrity rather than confidentiality or availability?
A ransomware attack encrypts all files, preventing access.
An attacker modifies system logs to erase traces of intrusion.
An insider exfiltrates sensitive financial data without authorization.
A DDoS attack renders a government portal inaccessible.
When digital forensic evidence is collected from an operating system, which principle ensures that the evidence remains admissible in court?
The evidence must be encrypted during collection to maintain confidentiality.
The evidence must follow a strict chain of custody to preserve integrity.
The evidence must be analyzed immediately after collection to avoid decay.
The evidence must be anonymized to protect privacy of third parties.
