CNIT 323/420 — Final Exam
What are the types of software forensic tools? - Answer-command line applications
GUI applications
What are commonly used to copy data from a suspect's disk drive to an image file? - Answer-software
forensic tools
ISO standard 27037 states: - Answer-Digital Evidence First Responders
(DEFRs) should use validated tools
When performing tasks using digital forensic tools, which guidelines should you follow? - Answer-NIST's
Computer Forensics Tool Testing (CFTT) program
What are the 5 major categories of tasks performed by digital forensics tools? - Answer-Acquisition
Validation and verification
Extraction
Reconstruction
Reporting
____________ is making a copy of the original drive - Answer-acquisition
,TRUE/FALSE
There are 2 types of data-copying methods used in software acquisitions. - Answer-TRUE
Physical copying of the entire drive
Logical copying of a disk partition
TRUE/FALSE
You can view a raw image file's contents with any hexadecimal editor - Answer-TRUE
What is a typical feature in vendor acquisition tools? - Answer-creating smaller segmented files
TRUE/FALSE
Remote acquisition of files is common in smaller organizations - Answer-FALSE
Larger organizations
Popular tools, such as AccessData and EnCase, can do remote acquisitions of forensics drive images on a
network
____________ is a way to confirm that a tool is functioning as intended - Answer-validation
______________ proves that two sets of data are identical by calculating hash values or using another
similar method - Answer-Verification
,_______________ is the confirmation by examination *and* the provision of objective evidence that a
tool, technique or procedure functions correctly *and* as intended - Answer-Validation
_______________ is the confirmation of a validation with laboratories' *tools*, techniques *and*
procedures. - Answer-Verification
CRC-32, MD5, SHA-1 are examples of ___________ - Answer-hashing
What are the subfunctions of verification? - Answer-Hashing
Filtering (based on hash value sets)
Analyzing file headers (discriminate files based on their types)
____________________ has compiled a list of known file (good and bad) hashes - Answer-National
Software Reference Library (NSRL)
TRUE/FALSE
Not many forensics tools can identify header values - Answer-FALSE
Most forensics tools can identify header values
___________ is the recovery task in a digital investigation - Answer-extraction
Which digital forensics tasks is the most challenging? - Answer-extraction
TRUE/FALSE
, Recovering data is the first step in analyzing an investigation's data - Answer-TRUE
What are the subfunctions of extraction? - Answer-Data viewing
Keyword searching
Decompressing or uncompressing
Carving
Decrypting
Bookmarking or tagging
TRUE/FALSE
Keyword search always speed up analysis for investigators - Answer-FALSE
TRUE/FALSE
From an investigation perspective, encrypted files and systems are a problem - Answer-TRUE
Many password recovery tools have a feature for generating potential password lists for a
_______________ attack - Answer-password dictionary
If a password dictionary attack fails, you can run a ______________ attack - Answer-brute-force
TRUE/FALSE
You should bookmark or record the findings during extraction and decryption - Answer-TRUE
What are the types of software forensic tools? - Answer-command line applications
GUI applications
What are commonly used to copy data from a suspect's disk drive to an image file? - Answer-software
forensic tools
ISO standard 27037 states: - Answer-Digital Evidence First Responders
(DEFRs) should use validated tools
When performing tasks using digital forensic tools, which guidelines should you follow? - Answer-NIST's
Computer Forensics Tool Testing (CFTT) program
What are the 5 major categories of tasks performed by digital forensics tools? - Answer-Acquisition
Validation and verification
Extraction
Reconstruction
Reporting
____________ is making a copy of the original drive - Answer-acquisition
,TRUE/FALSE
There are 2 types of data-copying methods used in software acquisitions. - Answer-TRUE
Physical copying of the entire drive
Logical copying of a disk partition
TRUE/FALSE
You can view a raw image file's contents with any hexadecimal editor - Answer-TRUE
What is a typical feature in vendor acquisition tools? - Answer-creating smaller segmented files
TRUE/FALSE
Remote acquisition of files is common in smaller organizations - Answer-FALSE
Larger organizations
Popular tools, such as AccessData and EnCase, can do remote acquisitions of forensics drive images on a
network
____________ is a way to confirm that a tool is functioning as intended - Answer-validation
______________ proves that two sets of data are identical by calculating hash values or using another
similar method - Answer-Verification
,_______________ is the confirmation by examination *and* the provision of objective evidence that a
tool, technique or procedure functions correctly *and* as intended - Answer-Validation
_______________ is the confirmation of a validation with laboratories' *tools*, techniques *and*
procedures. - Answer-Verification
CRC-32, MD5, SHA-1 are examples of ___________ - Answer-hashing
What are the subfunctions of verification? - Answer-Hashing
Filtering (based on hash value sets)
Analyzing file headers (discriminate files based on their types)
____________________ has compiled a list of known file (good and bad) hashes - Answer-National
Software Reference Library (NSRL)
TRUE/FALSE
Not many forensics tools can identify header values - Answer-FALSE
Most forensics tools can identify header values
___________ is the recovery task in a digital investigation - Answer-extraction
Which digital forensics tasks is the most challenging? - Answer-extraction
TRUE/FALSE
, Recovering data is the first step in analyzing an investigation's data - Answer-TRUE
What are the subfunctions of extraction? - Answer-Data viewing
Keyword searching
Decompressing or uncompressing
Carving
Decrypting
Bookmarking or tagging
TRUE/FALSE
Keyword search always speed up analysis for investigators - Answer-FALSE
TRUE/FALSE
From an investigation perspective, encrypted files and systems are a problem - Answer-TRUE
Many password recovery tools have a feature for generating potential password lists for a
_______________ attack - Answer-password dictionary
If a password dictionary attack fails, you can run a ______________ attack - Answer-brute-force
TRUE/FALSE
You should bookmark or record the findings during extraction and decryption - Answer-TRUE