Prep 2026 | Complete Review
1. Describe the role of a write blocker in forensic analysis.
A write blocker encrypts data to protect it from unauthorized access.
A write blocker ensures that the original data on a hard drive
remains unchanged during analysis.
A write blocker is used to create backups of data on the hard drive.
A write blocker allows for data recovery from damaged drives.
2. Describe how segmentation can enhance security for remote administration
interfaces.
Segmentation has no impact on security.
Segmentation simplifies the network architecture.
Segmentation can enhance security by isolating remote
administration interfaces from other network segments, reducing
the risk of unauthorized access.
Segmentation increases the number of users who can access the
network.
3. Describe why user authentication is essential for computers located in public
areas.
User authentication is essential to ensure that only authorized
individuals can access the system and protect sensitive information.
User authentication prevents all types of malware.
User authentication is only necessary for private networks.
User authentication is used to improve system performance.
,4. What classification in a vulnerability scan indicates a potential false positive?
Critical vulnerabilities identified by the scanner
Items classified by the system as Low or as For Informational
Purposes Only
Items flagged for immediate remediation
Findings that show the scanner compliance plug-ins are not up to
date
5. In a scenario where a company needs to restrict access to sensitive financial
data, which access control method would be most effective and why?
Mandatory Access Control (MAC) would be suitable as it enforces
strict policies regardless of user roles.
Discretionary Access Control (DAC) would be best as it allows users
to set their own permissions.
Attribute-Based Access Control (ABAC) would be ideal since it uses
user attributes to define access.
Role-Based Access Control (RBAC) would be most effective
because it allows access to be granted based on specific roles
related to financial responsibilities.
6. What type of attack is facilitated by excessive personal information shared on
social media?
Phishing attack
Denial of Service attack
Social engineering attack
Brute force attack
, 7. You are in the recovery steps of an incident response. Your analysis revealed
that the attacker exploited an unpatched vulnerability on a public-facing web
server as the initial intrusion vector in this incident. Which of the following
mitigations should be implemented first during the recovery?
Disable unused user account and reset the administrator credentials
Restrict shell commands per user or per host for least privilege
purposes
Restrict host access to peripheral protocols like USB and Bluetooth
Scan the network for additional instances of this vulnerability and
patch the affected assets
8. What is the primary tool used to prevent changes to a hard drive during
forensic analysis?
Data recovery software
Disk imaging tool
File encryption software
Write blocker
9. David noticed that port 3389 was open on one of the POS terminals in a
store during a scheduled PCI compliance scan. Based on the scan results,
what service should he expect to find enabled on this terminal?
LDAP
MySQL
RDP
IMAP