Forensics questions with accurate answers
Ans✓✓✓What is a best practice in preparing a report following an
incident response, as opposed to a criminal investigation?
· Keep in mind an incident response will never lead to a criminal
investigation.
· Only document your observations; don't include any opinions you have
drawn.
· Limit your documentation and narrative to what happened.
· Err on the side of additional documentation and evidence.
· An AD1 file is a combination file of the RAM and the swap file.
Ans✓✓✓As you begin your investigation you should capture an AD1
file. Why would you do this?
· An AD1 file is a combination file of the RAM and the swap file.
· An AD1 file is a combination of the RAM and the open files on the
computer.
· An AD1 file is an Accessed Demonstration file you will need for court.
· An AD1 file is an All Drives file that captures external media.
· an intellectual property digital forensics investigation Ans✓✓✓ABC
Publishing learns that the new novel by Jane Smith that it has not yet
sent to print is appearing on XYZ Booksellers in a full PDF version.
Which type of digital forensics investigation will ABC begin?
, · an administrative digital forensics investigation
· an intellectual property digital forensics investigation
· a criminal digital forensics investigation
· a civil digital forensics investigation
· Autopsy is a tool to help with forensic analysis using graphical event-
viewing interfaces. Ans✓✓✓What does the open-source tool Autopsy
do?
· Autopsy is a tool to help with forensic analysis by storing data into the
cloud.
· Autopsy is a tool to help with forensic analysis using graphical event-
viewing interfaces.
· Autopsy is a tool to help reconstruct the data on a computer hard drive.
· Autopsy is a tool to help with forensic analysis using mathematic
algorithms.
· Beaconing Ans✓✓✓When you arrive at the office you have been
called to, you learn that the finance manager's workstation is calling out
to the same IP address at a regular interval. This is an indication of
_____.
· Malware
· Imaging