Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?
Anetwork-based IDS systems (NIDS)
Bhost-based IDS systems (HIDS)
Canomaly detection
Dsignature recognition
What header field in the TCP/IP protocol stack involves the hacker exploit known as the Ping of Death?
AICMP header field
BTCP header field
CIP header field
DUDP header field
If you plan to startup a suspect's computer, you must modify the ___________ to ensure that you do not contaminate or alter data on the suspect's hard drive by booting to the hard drive.
Adeltree command
BCMOS
CBoot.sys
DScandisk utility
Area density refers to:
Athe amount of data per disk
Bthe amount of data per partition
Cthe amount of data per square inch
Dthe amount of data per platter
Question 6
Procedures and Methodology
0
Question 7
Procedures and Methodology
Question 8
Network Forensics
Question 9
Digital Evidence
Question 10
Network Forensics
Question 11
Digital Evidence
Question 12
Network Forensics
Question 13
Procedures and Methodology
Question 14
Digital Evidence
Question 15
Procedures and Methodology
Question 16
Digital Evidence
Question 17
Digital Evidence
Question 18
Regulations, Policies and Ethics
Question 19
Procedures and Methodology
Question 20
Procedures and Methodology
Question 21
Web Application Forensics
Question 22
Regulations, Policies and Ethics
Question 23
Procedures and Methodology
Question 24
Malware Forensics
Question 25
Digital Evidence
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?
Aforensic duplication of hard drive
Banalysis of volatile data
Ccomparison of MD5 checksums
Dreview of SIDs in the Registry
You have completed a forensic investigation case. You would like to destroy the data contained in various disks at the forensics lab due to sensitivity of the case.
How would you permanently erase the data on the hard disk?
AThrow the hard disk into the fire
BRun the powerful magnets over the hard disk
CFormat the hard disk multiple times using a low level disk utility
DOverwrite the contents of the hard disk with Junk data
Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using
Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?
AClosed
BOpen
CStealth
DFiltered
When examining a file with a Hex Editor, what space does the file header occupy?
Athe last several bytes of the file
Bthe first several bytes of the file
Cnone, file headers are contained in the FAT
Done byte at the beginning of the file
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?
AUse a system that has a dynamic addressing on the network
BUse a system that is not directly interacting with the router
CUse it on a system in an external DMZ in front of the firewall
DIt doesn't matter as all replies are faked
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
AThe system files have been copied by a remote attacker
BThe system administrator has created an incremental backup
CThe system has been compromised using a t0rnrootkit
DNothing in particular as these can be operational files
What is the target host IP in the following command?
A172.16.28.95
B10.10.150.1
CFirewalk does not scan target hosts
DThis command is using FIN packets, which cannot scan target hosts
What operating system would respond to the following command?
AWindows 95
BFreeBSD
CWindows XP
DMac OS X
Software firewalls work at which layer of the OSI model?
AApplication
BNetwork
CTransport
DData Link
What will the following command accomplish?
ATest ability of a router to handle over-sized packets
BTest the ability of a router to handle under-sized packets
CTest the ability of a WLAN to handle fragmented packets
DTest the ability of a router to handle fragmented packets
In a FAT32 system, a 123 KB file will use how many sectors?
A34
B25
C11
D56
How many sectors will a 125 KB file use in a FAT32 file system?
A32
B16
C256
D25
What should you do when approached by a reporter about a case that you are working on or have worked on?
ARefer the reporter to the attorney that retained you
BSay, "no comment"
CAnswer all the reporter's questions as completely as possible
DAnswer only the questions that help your case
What file is processed at the end of a Windows XP boot to initialize the logon dialog box?
ANTOSKRNL.EXE
BNTLDR
CLSASS.EXE
DNTDETECT.COM
What type of equipment would a forensics investigator store in a StrongHold bag?
APDAPDA?
BBackup tapes
CHard drives
DWireless cards
You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities: When you type this and click on search, you receive a pop-up window that says: "This is a test."
What is the result of this test?
AYour website is vulnerable to CSS
BYour website is not vulnerable
CYour website is vulnerable to SQL injection
DYour website is vulnerable to web bugs
When an investigator contacts by telephone the domain administrator or controller listed by a Who is lookup to request all e-mails sent and received for a user account be preserved, what U.S.C. statute authorizes this phone call and obligates the ISP to preserve e-mail records?
ATitle 18, Section 1030
BTitle 18, Section 2703(d)
CTitle 18, Section Chapter 90
DTitle 18, Section 2703(f)
Which password cracking technique uses details such as length of password, character sets used to construct the password, etc.?
ADictionary attack
BBrute force attack
CRule-based attack
DMan in the middle attack
Which response organization tracks hoaxes as well as viruses?
ANIPC
BFEDCIRC
CCERT
DCIAC
When a file is deleted by Windows Explorer or through the MS-DOS delete command, the operating system inserts _______________ in the first letter position of the filename in the FAT database.