Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 8 pages
Exam (elaborations)

DFCS 635 (DFCS635) unit 1 and 2 quizzes | questions and answers - latest 100% correct Winter 26 - UMGC.

Document preview thumbnail
Preview 2 out of 8 pages

DFCS 635 (DFCS635) unit 1 and 2 quizzes Unit 1 Quiz Question 1 (1 point) Which step is not one of the five steps of the NIST Framework? Question 1 options: Detect Identify Protect Recover Execute Question 2 (1 point) What is NOT a motivation for cyber threat actors? Question 2 options: Espionage Political Tampering Financial Gain System Optimization Question 3 (1 point) Which is NOT one of the six steps of the CVE process? Question 3 options: Record Publish Discover Request Submit ReserveQuestion 4 (1 point) What is MITRE ATT&CK? Question 4 options: MITRE ATT&CK is a high-performance computing environment run by MITRE. MITRE ATT&CK is a virtualization platform for running container images. MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations of cyberattacks. MITRE ATT&CK is an application executed to compromise vulnerable systems. Question 5 (1 point) MITRE creates or manages processes for all of the following, with the exception of what? Question 5 options: CVEs APTs ATT&CK CAR Question 6 (1 point) How can previous incident reports provide intelligence data when operationalizing MITRE ATT&CK? Question 6 options: By providing an analytical model for the blue team By providing a scope of work during purple teaming exercises By mapping the behaviors to tactics and technique By providing the red team with a templateQuestion 7 (1 point) All of the following are sources of data collection except for what? Question 7 options: Incident response reports File and registry monitoring Authentication logs collected from the domain controller Process and process command line monitoring Question 8 (1 point) These are specific implementations of how the adversary’s technical goals are achieved. Question 8 options: Tools Procedures Tactics Techniques Question 9 (1 point) This ATT&CK tactic results in adversary-controlled code running on a local or remote system. Question 9 options: Execution Initial access Privilege escalation Lateral movementQuestion 10 (1 point) TTPs describe actions taken by adversaries during a network attack. Question 10 options: True FalseUNIT 2 QUIZ Question 1 (1 point) What is a forensic image collection technique that captures all files that are visible to the user (but not lost or deleted items)? Question 1 options: None of the above A physical device collection A logical image of a device A target collection Question 2 (1 point) How does virtualization provide preservation? Question 2 options: Virtualization allows you to reset the machine image after each inspection change. A virtual machine ensures the original device remains untouched. A virtual machine doesn't provide any preservation capabilities. A virtual machine can be stored on a thumb drive for transport and safe keeping. Question 3 (1 point) What is the chain of custody? Question 3 options: The list of all employees of the crime lab A log of everyone who has read about the digitally collected evidence A documentation process that protects evidence from contamination and tampering and preserves evidence integrity A list of every artifact of evidence collectedQuestion 4 (1 point) What are type 1 hypervisors installed on? Question 4 options: USB drives and other detachable external media Customized machines built in the cloud A host operating system Bare metal systems allowing direct access to interact with hardware Question 5 (1 point) What is a forensic image collection technique that is constrained to a specific focus? Question 5 options: None of the above A target collection A physical device collection A logical image of a device Question 6 (1 point) What is a core advantage of using virtual machines for forensic investigation? Question 6 options: Isolation of forensic environments from the host system Integration of multiple operating systems into a single environment Ability to run games and graphics-intensive applications Access to a faster internet connectionQuestion 7 (1 point) What is a forensic image collection technique that is a bit-by-bit copy of the equipment? Question 7 options: A target collection A physical device collection A logical image of a device None of the above Question 8 (1 point) What does virtual machine isolation mean? Question 8 options: Virtual machines can only be accessed locally. Virtual machines run independently and are isolated from each other and the host system. Virtual machines share the same resources and cannot be isolated. Virtual machines can communicate directly with the physical hardware. Question 9 (1 point) What is the primary purpose of a hypervisor in virtualization? Question 9 options: To allocate hardware resources and manage virtual machines To create virtual hard disks To manage the network connections To manage the guest operating systemsQuestion 10 (1 point) What is the benefit for anti-forensics of virtual machine portability? Question 10 options: It reduces the need for hardware virtualization. It allows virtual machines to communicate with each other easily. It ensures faster boot times for virtual machines. It allows virtual machines to be moved between different physical machines with compatible hypervisors.

Content preview

Unit 1 Quiz


Question 1 (1 point)

Which step is not one of the five steps of the NIST Framework?
Question 1 options:
Detect
Identify
Protect
Recover
Execute


Question 2 (1 point)

What is NOT a motivation for cyber threat actors?
Question 2 options:
Espionage
Political Tampering
Financial Gain
System Optimization


Question 3 (1 point)

Which is NOT one of the six steps of the CVE process?
Question 3 options:
Record
Publish
Discover
Request
Submit
Reserve

, Question 4 (1 point)

What is MITRE ATT&CK?
Question 4 options:
MITRE ATT&CK is a high-performance computing environment run by MITRE.
MITRE ATT&CK is a virtualization platform for running container images.
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on
real-world observations of cyberattacks.
MITRE ATT&CK is an application executed to compromise vulnerable systems.


Question 5 (1 point)

MITRE creates or manages processes for all of the following, with the
exception of what?
Question 5 options:
CVEs
APTs
ATT&CK
CAR


Question 6 (1 point)

How can previous incident reports provide intelligence data when
operationalizing MITRE ATT&CK?
Question 6 options:
By providing an analytical model for the blue team
By providing a scope of work during purple teaming exercises
By mapping the behaviors to tactics and technique
By providing the red team with a template

Document information

Uploaded on
May 13, 2026
Number of pages
8
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$16.39

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
MindCraft
3.8
(47)
Sold
368
Followers
7
Items
2789
Last sold
3 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions