PERFORMANCE ASSESSMENT | COMPLETE INCIDENT
REPORT AND UNAUTHORIZED ACTIVITY ANALYSIS
ACTUAL EXAM 2026-2027 COMPLETE AND ACCURATE
EXAM QUESTIONS AND CORRECT VERIFIED ANSWERS
CURRENTLY UPDATED EXAM VERSION 2026 |FULL
REVISED EXAM |GUARANTEED PASS A+ |INSTANT
DOWNLOAD PDF
A digital forensic investigator arrives at the scene of a security incident involving a
live, running computer system. According to standard forensic best practices, what
is the most appropriate initial action regarding the system's power state?
A. Immediately pull the power cable from the system to prevent data loss.
B. Document the system state and consider the acquisition of volatile data.
C. Log in using the suspect's credentials to assess the active session.
D. Shut down the system using the operating system's normal shutdown procedure.
Answer: B
Rationale: The investigator should first document the system, assess the situation,
and preserve volatile data where authorized and appropriate, as volatile data like
memory contents and running processes can be lost when power is removed.
Pulling the power cable can cause data loss and is not the preferred first step;
,proper forensic procedures prioritize the acquisition of volatile evidence before any
other action. Logging into the system would alter the state of the evidence, and a
normal shutdown can also alter critical files and volatile data.
Which of the following best describes the primary purpose of a cryptographic hash
function in the context of digital forensics?
A. To encrypt the original evidence, preventing unauthorized access.
B. To generate a unique digital fingerprint of a piece of evidence to verify its
integrity.
C. To compress large files for more efficient storage of forensic images.
D. To recover the original data from a deleted file on a hard drive.
Answer: B
Rationale: A cryptographic hash function maps a variable-length string or message
to a fixed-size value, or message digest . This hash serves as a unique fingerprint;
any alteration to the original data, even a single bit, will result in a completely
different hash value. This is crucial for non-repudiation and to ensure that the
evidence has not been modified during the collection, preservation, and analysis
process .
What is an Indicator of Compromise (IOC) in the context of incident response?
A. A guaranteed proof that an employee has committed misconduct.
B. Artifacts observed on a network or operating system that suggest a possible
security breach.
C. A formal document that lists all the hardware replaced after an incident.
D. A legal requirement for an organization to report a data breach to authorities.
,Answer: B
Rationale: An IOC is evidence suggesting possible malicious activity, which can
include suspicious IP addresses, domain names, file hashes, registry keys, unusual
processes, and abnormal account activity . They are used to identify potential
compromises, but they are not by themselves absolute proof of an incident; they
signal that further investigation is warranted.
What is the primary objective of the "containment" phase of the incident response
process?
A. To completely remove the root cause of the incident from the environment.
B. To restore systems to normal operation and monitor for any recurring issues.
C. To limit the damage caused by the incident and prevent it from spreading.
D. To conduct a thorough analysis to identify the attacker's techniques and
motivations.
Answer: C
Rationale: The primary objective of containment is to limit the damage caused by
an incident and prevent it from spreading . An example of short-term containment
is isolating an affected endpoint from the network to stop lateral movement and
prevent further communication with malicious infrastructure .
When analyzing Windows Event Logs, which Event ID commonly indicates a
successful logon attempt by a user?
A. 4625
B. 4624
C. 1102
D. 4688
, Answer: B
Rationale: Event ID 4624 generally indicates a successful account logon . Event ID
4625, on the other hand, typically records failed authentication attempts . Event ID
1102 indicates that the security audit log was cleared, and Event ID 4688 is used
for process creation.
A forensic investigator observes a sequence of events in the Windows Security log:
dozens of failed logon attempts (Event ID 4625) from a single source, followed
immediately by a single successful logon (Event ID 4624). What type of attack
does this pattern most likely indicate?
A. A distributed denial-of-service (DDoS) attack.
B. A routine backup process running on the system.
C. A possible brute-force or password-spraying attack.
D. An attempt by a user to access a file they do not have permission to open.
Answer: C
Rationale: Repeated failed attempts followed by success can indicate credential
guessing or password spraying . Attackers often use automated tools to try many
passwords against a single account or try common passwords against many
accounts until they find one that works, resulting in this log pattern.
Which of the following is an example of a standard forensic tool used for creating
forensic images of hard drives, partitions, and files?
A. Wireshark
B. Metasploit
C. FTK Imager