• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 9 pages
Exam (elaborations)

CySA+ Chapter 9 – Preparing the Incident Response: Verified Questions and Forensics Tools Guide

Document preview thumbnail
Preview 2 out of 9 pages

This document compiles verified questions and detailed answers aligned with Chapter 9 of the CySA+ certification material, focused on preparing the incident response. Topics include Linux file paths, forensic imaging commands, hashing, digital evidence handling, live forensics, timeline analysis, and key tools like FTK, EnCase, dd, sha1sum, and Autopsy. Aimed at learners preparing for CySA+ and building strong forensic foundations.

Content preview

CySA+ Chapter 9: Preparing the Incident Response
questions with verified answers
/etc Ans✓✓✓This is the primary system configuration directory, which
contains a subdirectory for most installed applications


/home/$USER Ans✓✓✓Here, $USER is a variable name that you
should replace with the name of the given user. All user data and
configuration data is kept here


/var/log Ans✓✓✓All well-behaved Linux applications will keep their
log files in plaintext files in this directory, making it a gold mine for
analysts.


A junior analyst has two files and needs to verify they are exact
duplicates. To do this, the analyst konws to first create hashes from the
two files and then compare them. Which of the following tools from the
forensic kit is best tool to use?
A. dd
B. sha1sum
C. eventviewer
D. BitLocker Ans✓✓✓B. Sah1sum. The sha1sum will calculate and
check a SHA-1 hash value. The hash value is also known as a message
digest. The analyst will use sha1sum to calculate and compare message
digests of these two files

, Acquisition Ans✓✓✓IS the preserrvation of evidence in a legally
admissible manner.


Analysis Ans✓✓✓takes place in a controlled environment and without
unduly tainting the evidence.


As part fo the forensic analysis process, what critical activity often
includes a graphical representation of process and operating system
events? Ans✓✓✓Timeline Analysis


Chain of Custody Ans✓✓✓Is a history that shows how evidence was
collected, transported, and preserved at every stage of the process.
Should follow evidence through its entire life cycle, begining with
identification and ending with its destruction, permanent archiving, or
return to the owner.


Command line input:
dd if=/dev/sda of=/dev/sdc bs=2048 conv=noerror,sync status=progress


How many bits of data are read and written at a time? Ans✓✓✓16384:
The bs argument indicates the number of bytes transferring during the
process. Because there are 8 bits in a byte, you can multiply the 2048 by
8 to get 16384 bits.


Command line input:
dd if=/dev/sda of=/dev/sdc bs=2048 conv=noerror,sync status=progress

Document information

Uploaded on
June 26, 2025
Number of pages
9
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions