• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 17 pages
Exam (elaborations)

WGU C702 CHFI and OA Graded A+ (2023)

Document preview thumbnail
Preview 3 out of 17 pages

WGU C702 CHFI and OA Graded A+ (2023) Which of the following is true regarding computer forensics? - ANSWER-Computer forensics deals with the process of finding evidence related to a digital crime to find the culprits and initiate legal action against them. Which of the following is NOT a objective of computer forensics? - ANSWER-Document vulnerabilities allowing further loss of intellectual property, finances, and reputation during an attack. Which of the following is true regarding Enterprise Theory of Investigation (ETI)? - ANSWER-It adopts a holistic approach toward any criminal activity as a criminal operation rather as a single criminal act. Forensic readiness refers to: - ANSWER-An organization's ability to make optimal use of digital evidence in a limited time period and with minimal investigation costs. Which of the following is NOT a element of cybercrime? - ANSWER-Evidence smaller in size. Which of the following is true of cybercrimes? - ANSWER-Investigators, with a warrant, have the authority to forcibly seize the computing devices. Which of the following is true of cybercrimes? - ANSWER-The initial reporting of the evidence is usually informal. Which of the following is NOT a consideration during a cybercrime investigation? - ANSWER-Value or cost to the victim. Which of the following is a user-created source of potential evidence? - ANSWERAddress book. Which of the following is a computer-created source of potential evidence? - ANSWERSwap file. Which of the following is NOT where potential evidence may be located? - ANSWERProcessor. Under which of the following conditions will duplicate evidence NOT suffice? - ANSWER-When original evidence is in possession of the originator. Which of the following Federal Rules of Evidence governs proceedings in the courts of the United States? - ANSWER-Rule 101. Which of the following Federal Rules of Evidence ensures that the truth may be ascertained and the proceedings justly determined? - ANSWER-Rule 102. Which of the following Federal Rules of Evidence contains rulings on evidence? - ANSWER-Rule 103 Which of the following Federal Rules of Evidence states that the court shall restrict the evidence to its proper scope and instruct the jury accordingly? - ANSWER-Rule 105 Which of the following refers to a set of methodological procedures and techniques to identify, gather, preserve, extract, interpret, document, and present evidence from computing equipment in such a manner that the discovered evidence is acceptable during a legal and/or administrative proceeding in a court of law? - ANSWER-Computer Forensics. Computer Forensics deals with the process of finding related to a digital crime to find the culprits and initiate legal action against them. - ANSWER-Evidence. Minimizing the tangible and intangible losses to the organization or an individual is considered an essential computer forensics use. - ANSWER-True. Cybercrimes can be classified into the following two types of attacks, based on the line of attack. - ANSWER-Internal and External. Espionage, theft of intellectual property, manipulation of records, and trojan horse attacks are examples of what? - ANSWER-Insider attack or primary attacks. External attacks occur when there are inadequate information-security policies and procedures. - ANSWER-True. Which type of cases involve disputes between two parties? - ANSWER-Civil. A computer forensic examiner can investigate any crime as long as he or she takes detailed notes and follows the appropriate processes. - ANSWER-False. is the standard investigative model used by the FBI when conducting investigations against major criminal organizations. - ANSWER-Enterprise Theory of Investigation (ETI). Forensic readiness includes technical and nontechnical actions that maximize an organization's competence to use digital evidence. - ANSWER-True. Which of the following is the process of developing a strategy to address the occurrence of any security breach in the system or network? - ANSWER-Incident Response. Digital devices store data about session such as user and type of connection. - ANSWER-True. Codes of ethics are the principles stated to describe the expected behavior of an investigator while handling a case. Which of the following is NOT a principle that a computer forensic investigator must follow? - ANSWER-Provide personal or prejudiced opinions. What must an investigator do in order to offer a good report to a court of law and ease the prosecution? - ANSWER-Preserve the evidence. What is the role of an expert witness? - ANSWER-To educate the public and court. Which of the following is NOT a legitimate authorizer of a search warrant? - ANSWERFirst Responder. Under which of the following circumstances has a court of law allowed investigators to perform searches without a warrant? - ANSWER-Delay in obtaining a warrant may lead to the destruction of evidence and hamper the investigation process. Which of the following should be considered before planning and evaluating the budget for the forensic investigation case? - ANSWER-Breakdown of costs into daily and annual expenditure. Which of the following should be physical location and structural design considerations for forensics labs? - ANSWER-Lab exteriors should have no windows. Which of the following should be work area considerations for forensics labs? - ANSWER-Examiner station has an area of about 50-63 square feet. Which of the following is NOT part of the Computer Forensics Investigation Methodology? - ANSWER-Testify as an expert defendant. Which of the following is NOT part of the Computer Forensics Investigation Methodology? - ANSWER-Destroy the evidence. Investigators can immediately take action after receiving a report of a security incident. - ANSWER-False. In forensics laws, "authenticating or identifying evidences" comes under which rule? - ANSWER-Rule 901. Courts call knowledgable persons to testify to the accuracy of the investigative process. These people who tesify are known as the: - ANSWER-Expert witnesses. A chain of custody is a critical document in the computer forensics investigation process because the document provides legal validation of appropriate evidence handling. - ANSWER-True. Identify the following which was launched by the National Institute of Standards and Technology (NIST), that establishes a "methodology for testing computer forensics software tools by development of general tool specifications, test procedures, test criteria, test sets, and test hardware." - ANSWER-Computer Forensic Tool Testing Project (CFTTP) Which of the following is NOT a digital data storage type? - ANSWER-Quantum storage devices. Which of the following is NOT a common computer file system? - ANSWER-EFX3 Which field type refers to the volume descriptor as a primary? - ANSWER-Number 1 Which logical drive holds the information regarding the data and files that are stored in the disk? - ANSWER-Extended partition. How large is the partition table structure that stores information about the partitions present on the hard disk? - ANSWER-64-byte. How many bits are used by the MBR partition scheme for storing LBAs (Logical Block Addresses) and the size information on a 512-byte sector? - ANSWER-32 bits in the GUID Partition Table, which Logical Block Address contains the Partition Entry Array? - ANSWER-LBA 2 Which of the following describes when the user restarts the system via the operating system? - ANSWER-Warm booting. Which Windows operating system power on and starts up using either the traditional BIOS-MBR method or the newer UEFI-GPT method? - ANSWER-Windows 8. Which item describes the following UEFI boot process phase? The phase of EFI consisting of initializing the CPU, temporary memory, and boot firmware volume (BFV); locating and executing the chapters to initialize all the found hardware in the system; and creating a Hand-Off Block List with all found resources interface descriptors. - ANSWER-PEI (Pre-EFI Initialization) Phase. Which of the following basic partitioning tools displays details about the GPT partition tables in Windows OS? - ANSWER-DiskPart. What stage of the Linux boot process includes the task of loading the Linux kernel and optional initial RAM disk? - ANSWER-Bootloader Stage What component of a typical FAT32 file system consists of data that the document framework uses to get to the volume and utilizes the framework parcel to stack the working portion documents? - ANSWER-Boot Sector. Which component of the NTFS architecture is a computer system file driver for NTFS? - ANSWER-N What is the name of the abstract layer that resides on top of a complete file system, allows client application to access various file systems, and consists of a dispatching layer and numerous caches? - ANSWER-Virtual File System (VFS) Which information held by the superblock contains major and minor items that allow the mounting code to determine whether or not supported features are available to the file system? - ANSWER-Revision Level. Which file system used in Linux was developed by Stephen Tweedie in 2001 as a journaling file system that improves reliability of the system? - ANSWER-Ext3 How many bit values does HFS use to address allocation blocks? - ANSWER-16 What UFS file system part is composed of a few blocks in the partition reserved at the beginning? - ANSWER-Boot blocks. What is a machine readable language used in major digital operations, such as sending and receiving emails? - ANSWER-ASCII What is JPEG an acronym of? - ANSWER-Joint Photographic Experts Group What is the proprietary Microsoft Office presentation file extension used in PowerPoint? - ANSWER-PPT Which of the following is an example of optical media? - ANSWER-CD/DVD In sector, addressing determines the address of the individual sector on the disk. - ANSWER-Cylinders, Heads, and Sectors (CHS) is a 128 bit unique reference number used as an identifier in computer software? - ANSWER-Global Unique Identifier (GUID) Mac OS uses a hierarchical file system. - ANSWER-True. The main advantage of RAID is that if a single physical disk fails: - ANSWER-The system will continue to function without loss of data. The command "fsstat" displays the details associated with an image file. - ANSWERFalse. What is the simplest RAID level that does not involve redundancy, and fragments the file into the user-defined stripe size of the array? - ANSWER-RAID 0 An investigator may commit some common mistakes while collecting data from the system that result in the loss of critical evidence. Which of the following is NOT a mistake that investigators commonly make? - ANSWER-Use of correct cables and cabling techniques. In Linux Standard Tools, forensic investigators use the following build-in Linux Commands to copy data from a disk drive: - ANSWER-dd and dcfldd Because they are always changing, the information in the registers or the processor cache are the most volatile data. - ANSWER-True. Forensic data duplication involves the creation of a file that has every bit of information from the source in a raw bit-stream format. - ANSWER-True. What document is used as a written record consisting of all processes involved in seizure, custody, control, transfer, analysis, and disposition of physical or electronic evidence? - ANSWER-Chain of custody document. What is the process of permanently deleting or destroying data from storage media? - ANSWER-Media sanitization. The process of acquiring volatile data from working computers )locked or in sleep condition) that are already powered on is: - ANSWER-Live data acquisition. Which of the following refers to the data stored in the registries, cache, and RAM of digital devices? - ANSWER-Volatile information. Where are deleted items stored on Windows Vista and later versions of Windows? - ANSWER-Drive;$Recycle.Bin Where are deleted items stored on Windows 98 and earlier versions of Windows? - ANSWER-Drive:RECYCLED Where are deleted items stored on the Windows 2000, XP, and NT versions of Windows? - ANSWER-Drive:RECYCLER What is the maximum size limit for the Recycle Bin in Windows prior to Windows Vista? - ANSWER-3.99GB Which of the following is NOT a feature of the Recover My Files tool? - ANSWERrecovering files from a network drive. What tool is used for format recovery, unformatting and recovering deleted files emptied from the Recycle Bin, or data lost due to partition loss or damage, software crash, virus infection, or unexpected shutdown and supports hardware RAID - ANSWER-EaseUS Which tool undeletes and recovers lost files from hard drives, memory cards, and USB flash drives? - ANSWER-Disk Digger Which tool recovers files that have been lost, deleted, corrupted, and even deteriorated? - ANSWER-Quick Recovery Which tool recovers lost data from hard drives, RAID, photographs, deleted files, iPods, and removable disks connected via FireWire or USB? - ANSWER-Total Recall Which tool scans the entire system for deleted files and folders and recovers them? - ANSWER-Advanced Disk Recovery Which tool for MAC recovers files from a crashed or virus- corrupted hard drive? - ANSWER-Data Rescue 4 Which of the following are frequently left by criminals, assisting investigators in understanding the process of crime and the motive behind it, and allowing them to attempt to identify the person(s) who committed it? - ANSWER-Fingerprints In Detecting Rootkits, the following technique is used to compare characteristics of all system processes and executable files with a database of known rootkit fingerprints. - ANSWER-Signature-Based Detection In Anti Forensics Techniques, which of the following techniques is used to hide a secret message within an ordinary message and extract it at the destination to maintain confidentiality of data? - ANSWER-Steganography Which of the following consists of volatile storage? - ANSWER-RAM What is NOT a command used to determine logged-on users? - ANSWERLoggedSessions What is NOT a command used to determine open files - ANSWER-Open files What command is used to determine the NetBIOS name table cache in Windows? - ANSWER-Nbtstat Which tool helps collect information about network connections operative in a Windows system? - ANSWER-Netstat Which of the following commands is NOT a command used to determine running processes in Windows? - ANSWER-Netstat Which is a completely open collection of tools, implemented in Python under the GNU General Public License, for the extraction of digital artifacts from volatile memory (RAM) samples? - ANSWER-Volatility Framework The information about the system users is stored in which file? - ANSWER-SAM database file The value 0 associated with the registry entry Enable Prefetcher tells the system to use which prefetch? - ANSWER-Prefetching is disabled. What prefetch does value 1 from the registry entry EnablePrefetcher tell the system to use? - ANSWER-Application prefetching is enabled. What prefetch does value 2 from the registry entry EnablePrefetcher tell the system to use? - ANSWER-Boot prefetching is enabled. What prefetch does the value 3 from the registry entry EnablePrefetcher tell the system to use? - ANSWER-Both application and boot prefetching are enabled. What tool enables you to retrieve information about event logs and publishers in Windows 10? - ANSWER-Wevtutil. Intruders attempting to gain remote access to a system try to find the other systems connected to the network and visible to the compromised system. - ANSWER-True. command is used to display the network configuration of the NICs on the system. - ANSWER-ipconfig /all Investigators can use Linux commands to gather necessary information from the system. Identify the following shell command that is used to display the kernel ring buffer or information about device drivers loaded into the kernel. - ANSWER-dmesg What are the unique identification numbers assigned to Windows user account for granting user access to particular resources? - ANSWER-Microsoft security ID. In the Windows Event Log File internals, the following file is used to store the Databases related to the system: - ANSWER-S Thumbnails of images remain on computers even after files are deleted. - ANSWERTrue What is NOT one of the three tiers a log management infrastructure typically comprises? - ANSWER-Log rotation Which is NOT a log management system function? - ANSWER-Log generation. What is NOT one of the three major concerns regarding log management? - ANSWERLog viewing Which is a type of network-based attack? - ANSWER-Eavesdropping Which attack does NOT directly lead to unauthorized access? - ANSWER-Denial of service How can an attacker exploit a network? - ANSWER-Through wired or wireless connections. What is the primary reason for forensic investigators to examine logs? - ANSWER-To gain an insight into events that occurred in the affected devices/network. Which is true about the transport layer in the TCP/IP model? - ANSWER-It is the backbone for data flow between two devices in a network. What is an ongoing process that returns results simultaneously so that the system or operators can respond to attacks immediately? - ANSWER-Real time analysis Which of the following is an internal network vulnerability? - ANSWER-bottleneck Which attack is specific to wireless networks? - ANSWER-Jamming signal attack. Where can congressional security standards and guidelines be found, along with an emphasis for federal agencies to develop, document, and implement organization-wide programs for information security? - ANSWER-FISMA What requires companies that offer financial products or services to protect customer information against security threats? - ANSWER-GLBA Which of the following includes security standards for health information? - ANSWERHIPAA What is the act passed by the U.S. Congress to protect investors from the possibility of fraudulent accounting activities by corporations? - ANSWER-SOX What is a proprietary information security standard for organizations that handle cardholder information for major debit, credit, prepaid, e-purse, ATM, and POS cards? - ANSWER-PCI DSS In what type of forensic examination do investigators perform an examination of logs to detect something that has already occurred in a network/device and determine what it is? - ANSWER-Postmortem What are the most common network attacks launched against wireless networks? - ANSWER-AP MAC spoofing In Event Correlation Approaches, which approach is used to monitor the computers and computer users behavior and provide an alert if something anomalous is found? - ANSWER-Role-based approach The investigator uses which of the following commands to view the ARP table in Windows? - ANSWER-arp -a Which is NOT an indication of a web attack? - ANSWER-logs found to have no known anomalies. Which is a threat to web applications? - ANSWER-Cookie poisoning. What layer of web application architecture includes all the web appliances, such as smartphones and PCs, where interaction with a web application deployed on a web server occurs? - ANSWER-Client layer What layer of web application architecture contains components that parse the request (HTTP Request Parser) coming in and forwards the response back? - ANSWER-Web server layer What layer of web application architecture is responsible for the core functioning of the system and includes logic and application, such as .NET, used by developers to build websites according to client requirements? - ANSWER-Business layer What layer of web application architecture is composed of cloud services that hold all commercial transactions and a server that supplies an organization's production data in a structured form? - ANSWER-Database layer Which web application threat occurs when the application fails to guard memory properly and allows writing beyond maximum size? - ANSWER-Buffer overflow Which web application threat refers to the modification of a website's remnant data for bypassing security measures or gaining unauthorized information? - ANSWER-Cookie poisoning Which web application threat occurs when an attacker is allowed to gain access as a legitimate user to a web application or dad such as account records, credit card numbers, passwords, or other authenticated information? - ANSWER-Insecure storage. Which web application threat refers to a drawback in a web application where it unintentionally reveals sensitive data to an unauthorized user? - ANSWER-Information leakage. Which web application threat arises when a web application is unable to handle technical issues properly and the website returns information, such as database dumps, stack traces, and codes? - ANSWER-Improper error handling Which web application threat refers to vulnerable management functions, including user updates, recovery of passwords, or resetting passwords? - ANSWER-Broken account management Which web application threat occurs when attackers exploit HTTP, gain access to unauthorized directories, and execute commands outside the web server's root directory? - ANSWER-Directory traversal Which web application threat occurs when attackers insert commands via input data and are able to tamper with the data? - ANSWER-SQL injection Which web application threat occurs when attackers intend to manipulate the communication exchanged between the client and server to make changes in application data? - ANSWER-parameter tampering Which web application threat is a method intended to terminate website or server operations by making resources unavailable to clients? - ANSWER-Denial of service Which web application threat occurs when attackers tamper with the URL, HTTP requests, headers, hidden fields, form fields, or query strings? - ANSWER-Unvalidated input. Which web application threat occurs when attackers bypass the client's ID security mechanisms, gain access privileges, and inject malicious scripts into specific fields in web pages? - ANSWER-Cross site scripting Which web application threat occurs when attackers insert malicious code, commands, or scripts into the input gates of web applications, enabling the applications to interpret and run the newly supplied malicious input? - ANSWER-Injection flaws Which web application threat occurs when an authenticated user is forced to perform certain tasks on the web application chosen by an attacker? - ANSWER-Cross site request forgery Which web application threat occurs when attackers identify a flaw, bypass authentication, and compromise the network? - ANSWER-Broken access control Which supports HTTP, HTTPS, FTP, SMTP, and NNTP? - ANSWER-Internet Information Server (IIS) On Windows Server 2012, by default, the IIS log files are stored at which of the following locations? - ANSWER-%SystemDrive%inetpubLogsLogFiles Which of the following is a web analytics solution for small and medium size websites? - ANSWER-Deep log analyzer Which command is used to find if TCP and UDP ports have unusual listening? - ANSWER-netstat -na Which of the three different files storing data and logs in SQL servers holds the entire log information associated with the database? - ANSWER-LDF Which of the three different files storing data and logs in SQL servers is optional - ANSWER-NDF What file format is used by Windows Vista and later versions to store event logs as simple text files in XML format? - ANSWER-EVTX What type of forensics takes actions when a security incident has occurred and both detection and analysis of the malicious activities performed by criminals over the SQL database file are required? - ANSWER-MSSQL forensics For Forensics Analysis, which of the following MySQL Utility Programs is used to export metadata, data, or both from one or more databases? - ANSWER-mysqldbexport Which command line utility is used to take a backup of the database? - ANSWERmysqldump Which of the three different files storing data and logs in SQL servers is the starting point of a database and points to other files in the database? - ANSWER-MDF What cloud service offers a platform for developing applications and services? - ANSWER-PaaS What cloud service enables subscribers to use fundamental IT resources - such as computing power, virtualization, data storage, networ, etc. -on demand? - ANSWERIaaS What cloud service offers application software to subscribers on demand or over the internet and is charged for by the provider on a pay per use basis, by subscription, by advertising, or by sharing among multiple users? - ANSWER-SaaS Which of the following is also known as an internal or corporate cloud infrastructure that a single organization operates? - ANSWER-Private cloud What is a cloud environment composed of two or more clouds that remain unique entities but are bound together to offer the benefits of multiple deployment models? - ANSWER-Hybrid cloud Which cloud environment is a multi tenant infrastructure shared among organization with common computing concerns, such as security, regulatory compliance, performance requirements, and jurisdiction? - ANSWER-Community cloud Which cloud environment allows the provider to make services- such as application, servers, and data storage-available to the public over the internet? - ANSWER-Public cloud Which of the following stakeholders includes professionals- such as cloud security architects, network administrators, security administrators, and ethical hackersresponsible for managing and maintaining all aspects of the cloud? - ANSWER-IT professionals Which of the following stakeholders is responsible for conducting forensic examinations against allegations made regarding wrongdoings, found vulnerabilities, and attacks over the cloud? - ANSWER-Investigators Which of the following stakeholders are the first responders for all the security events or occurrences taking place on a cloud? - ANSWER-Incident handlers Which of the following stakeholders are responsible to make sure all the forensic activities are within the jurisdiction and not violating any regulations or agreements? - ANSWER-Law advisors What type of cloud testing should organizations perform regularly to monitor their security posture? - ANSWER-Pen testing On demand is a type of service rendered by cloud service providers that allow provisions for cloud resources such as computing power, storage, network, and so onalways on demand, without the need for human interaction with service providers. - ANSWER-Self service Identify the following Cloud computing services that enable subscribers to use fundamental IT resources such as computing power, virtualization, data storage, network, and so on- on demand. - ANSWER-Infrastructure-as-a-service (IaaS) On Windows 10 OS, by default, the Google Drive Client is installed at which of the following locations? - ANSWER-C:Program Files (x86)GoogleDrive Which of the following is a disadvantage of a private cloud? - ANSWER-Expense What is a common technique used to distribute malware on the web by injecting malware into legitimate looking websites to trick users into selecting them? - ANSWERClick jacking


Document information

Uploaded on
May 12, 2023
Number of pages
17
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers
$20.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
nishstuvia
4.8
(39)
Sold
39
Followers
38
Items
295
Last sold
2 year ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.