with accurate answers
100. While reviewing the actions taken during an incident response
process , Mei is informed by the local desktop support staff person that
the infected machine was returned to service by using a Windows
System Restore point . Which of the following items will a Windows
System Restore return to a previous state ? A. Personal files B. Malware
C. Windows system files D. All installed apps Ans✓✓✓A
101. During a major incident response effort , Kobe discovers evidence
that a critical application server may have been the data repository and
egress point in the compromise he is investigating . If he is unable to
take the system offline , which of the following options will provide him
with the best forensic data ? A. Reboot the server and mount the system
drive using a USB - bootable forensic suite . B. Create an image using a
tool like FTK Imager Lite . C. Capture the system memory using a tool
like Volatility . D. Install and run an imaging tool on the live server .
Ans✓✓✓A
104. During the preparation phase of his organization's incident response
process , Oscar gathers a laptop with useful software including a sniffer
and forensics tools , thumb drives and external hard drives , networking
equipment , and a variety of cables . What is this type of preprepared
equipment commonly called ? A. A grab bag B. A jump kit C. A crash
cart D. A first responder kit Ans✓✓✓A
105. As John proceeds with a forensic investigation involving numerous
images , he finds a directory labeled Downloaded from Facebook . The
images appear relevant to his investigation , so he processes them for
,metadata using exiftool . The following image shows the data provided .
What forensically useful information can John gather from this output
Ans✓✓✓A
106. Which of the following properly lists the order of volatility from
least to most volatile ? A. Printouts , swap files , CPU cache , RAM B.
Hard drives , USB media , DVDs , CD - RWS C. DVDs , hard drives ,
virtual memory , caches D. RAM , swap files , SSDs , printouts
Ans✓✓✓A
107. While conducting a forensic review of a system involved in a data
breach , Alex discovers a number of Microsoft Word files including files
with filenames like critical_data.docx and sales_estimates_2023.docx .
When he attempts to review the files using a text editor for any useful
information , he finds only unreadable data . What has occurred ? A.
Microsoft Word files are stored in ZIP format . B. Microsoft Word files
are encrypted . C. Microsoft Word files can be opened only by Microsoft
Word . D. The user has used antiforensic techniques to scramble the data
. Ans✓✓✓A
107. While conducting a forensic review of a system involved in a data
breach , Alex discovers a number of Microsoft Word files including files
with filenames like critical_data.docx and sales_estimates_2023.docx .
When he attempts to review the files using a text editor for any useful
information , he finds only unreadable data . What has occurred ? A.
Microsoft Word files are stored in ZIP format . B. Microsoft Word files
are encrypted . C. Microsoft Word files can be opened only by Microsoft
Word . D. The user has used antiforensic techniques to scramble the data
. Ans✓✓✓A
, 108. Lukas believes that one of his users has attempted to use built - in
Windows commands to probe servers on the network he is responsible
for . How can he recover the command history for that user if the system
has been rebooted since the reconnaissance has occurred ? A. Check the
Bash history . B. Open a command prompt window and press F7 . C.
Manually open the command history from the user's profile directory .
D. The Windows command prompt does not store command history .
Ans✓✓✓A
108. Lukas believes that one of his users has attempted to use built - in
Windows commands to probe servers on the network he is responsible
for . How can he recover the command history for that user if the system
has been rebooted since the reconnaissance has occurred ? A. Check the
Bash history . B. Open a command prompt window and press F7 . C.
Manually open the command history from the user's profile directory .
D. The Windows command prompt does not store command history .
Ans✓✓✓A
109. Angela is conducting an incident response exercise and needs to
assess the economic impact on her organization of a $ 500,000 expense
related to an information security incident . How should she categorize
this ? A. Low impact . B. Medium impact . C. High impact . D. Angela
cannot assess the impact with the data given . Ans✓✓✓A
110. What step follows sanitization of media according to NIST
guidelines for secure media handling ? A. Reuse . B. Validation C.
Destruction . D.Documentation . Ans✓✓✓A