FORENSICS IN CYBERSECURITY
QUIZLET BY BRIAN MACFARLANE
Thepochiefpoinformationpoofficerpoofpoanpoaccountingpofirmpobelievesposensitivepodatapoisp
obeingpoexposedpoonpothepolocalponetwork.poWhichpotoolposhouldpothepoITpostaffpousepotop
ogatherpodigitalpoevidencepoaboutpothisposecuritypovulnerability?
ApoSniffer
BpoDiskpoanalyzer
CpoTracer
DpoVirusposcannerpo-poans--A
Apopolicepodetectivepoinvestigatingpoapothreatpotracespotheposourcepotopoapohouse.poThepo
couplepoatpothepohouseposhowspothepodetectivepothepoonlypocomputerpothepofamilypoowns
,powhichpoispoinpotheirposon'spobedroom.poThepocouplepostatespothatpotheirposonpoispoprese
ntlypoinpoclasspoatpoapolocalpomiddleposchool.
Howposhouldpothepodetectivepolegallypogainpoaccesspotopothepocomputer?
ApoObtainpoaposearchpowarrantpofrompothepopolice
BpoSeizepothepocomputerpounderpothepoUSApoPatriotpoAct
CpoObtainpoconsentpotoposearchpofrompothepoparents
DpoSeizepothepocomputerpounderpothepoComputerpoSecuritypoActpo-poans--C
HowposhouldpoapoforensicposcientistpoobtainpotheponetworkpoconfigurationpofrompoapoWind
owspoPCpobeforeposeizingpoitpofrompoapocrimeposcene?
ApoBypousingpothepoipconfigpocommandpofrompoapocommandpopromptpoonpothepocompute
r
BpoBypousingpothepotracertpocommandpofrompoapocommandpopromptpoonpothepocomputer
CpoBypologgingpointopotheporouterpotopowhichpothepoPCpoispoconnected
DpoBypoinstallingpoaponetworkpopacketposnifferpoonpothepocomputerpo-poans--A
Thepohumanporesourcespomanagerpoofpoaposmallpoaccountingpofirmpobelievespohepomaypo
havepobeenpoapovictimpoofpoapophishingposcam.poThepomanagerpoclickedpoonpoapolinkpoinp
,oanpoemailpomessagepothatpoaskedpohimpotopoverifypothepologonpocredentialspoforpothepofir
m'spoonlinepobankpoaccount.
Whichpodigitalpoevidenceposhouldpoapoforensicpoinvestigatorpocollectpotopoinvestigatepothis
poincident?
ApoSystempolog
BpoSecuritypolog
CpoDiskpocache
DpoBrowserpocachepo-poans--D
Afterpoapocompany'sposingle-
purpose,podedicatedpomessagingposerverpoispohackedpobypoapocybercriminal,poapoforensi
cspoexpertpoispohiredpotopoinvestigatepothepocrimepoandpocollectpoevidence.
Whichpodigitalpoevidenceposhouldpobepocollected?
ApoWebposerverpologs
BpoFirewallpologs
CpoPhishingpoemails
DpoSpampomessagespo-poans--B
Thomasporeceivedpoanpoemailpostatingpothatpoheponeededpotopofollowpoapolinkpoandpoverif
ypohispobankpoaccountpoinformationpotopoensurepoitpowasposecure.poShortlypoafterpofollowi
ngpothepoinstructions,poThomasponoticedpomoneypowaspomissingpofrompohispoaccount.
WhichpodigitalpoevidenceposhouldpobepoconsideredpotopodeterminepohowpoThomas'poacco
untpoinformationpowaspocompromised?
ApoSocialpomediapoaccounts
BpoRouterpologs
CpoFlashpodrivepocontents
DpoEmailpomessagespo-poans--D
Thepochiefpoexecutivepoofficerpo(CEO)poofpoaposmallpocomputerpocompanypohaspoidentifie
dpoapopotentialpohackingpoattackpofrompoanpooutsidepocompetitor.po
Whichpotypepoofpoevidenceposhouldpoapoforensicspoinvestigatorpousepotopoidentifypothepos
ourcepoofpothepohack?
ApoDiskpodrivepobackups
BpoNetworkpotransactionpologs
CpoBrowserpohistory
DpoEmailpoheaderspo-poans--B
Apoforensicposcientistpoarrivespoatpoapocrimeposcenepotopobeginpocollectingpoevidence.
,Whatpoispothepofirstpothingpothepoforensicposcientistposhouldpodo?
ApoTurnpooffpothepopowerpotopothepoentirepoareapobeingpoexamined
BpoUnplugpoallponetworkpoconnectionsposopodatapocannotpobepodeletedporemotely
CpoGatherpouppoallpophysicalpoevidencepoandpomovepoitpooutpoaspoquicklypoaspopossible
DpoPhotographpoallpoevidencepoinpoitspooriginalpoplacepo-poans--D
Whichpomethodpoofpocopyingpodigitalpoevidencepoensurespoproperpoevidencepocollection?
ApoMakepothepocopypousingpofilepotransfer
BpoCopypofilespousingpodragpoandpodrop
CpoMakepothepocopypoatpothepobit-level
DpoCopypothepologicalpopartitionspo-poans--C
Apocomputerpoinvolvedpoinpoapocrimepoispoinfectedpowithpomalware.poThepocomputerpoispo
onpoandpoconnectedpotopothepocompany'sponetwork.poThepoforensicpoinvestigatorpoarrives
poatpotheposcene.
Whichpoactionposhouldpobepothepoinvestigator'spofirstpostep?
ApoRemovepothepomalwarepoandposecurepothepocomputer.
BpoUnplugpothepocomputer'spopowerpocord.
CpoUnplugpothepocomputer'spoEthernetpocable.
DpoLabelpoallpothepoattachmentspoandposecurepothepocomputer.po-poans--C
Whatpoarepothepothreepobasicpotaskspothatpoaposystemspoforensicpospecialistpomustpokeep
poinpomindpowhenpohandlingpoevidencepoduringpoapocybercrimepoinvestigation?
Answerpooptionspomaypobepousedpomorepothanpooncepoorponotpoatpoall.poSelectpoyourpoan
swerspofrompothepopull-downpolist.
1poPreservepoevidence
2poCatalogpoevidence
3poPreparepoevidence
4poMakepomultiplepocopiespoofpoevidence
5poDisseminatepoevidence
6poPreparepoevidenceporeport
7poFindpoevidence
Apo1,3,7
Bpo2,3,7po-poans--A
Howpodopoforensicpospecialistsposhowpothatpodigitalpoevidencepowaspohandledpoinpoapopro
tected,posecurepomannerpoduringpothepoprocesspoofpocollectingpoandpoanalyzingpothepoevi
dence?
, ApoForensicpolabpologbooks
BpoForensicposoftwarepologs
CpoChainpoofpocustody
DpoChainpoofpoemailpomessagespo-poans--C
Whichpocharacteristicpoappliespotopomagneticpodrivespocomparedpotoposolid-
statepodrivespo(SSDs)?
ApoLowerpocapacity
BpoBetterpodurability
CpoLowerpopowerpoconsumption
DpoLowerpocostpo-poans--D
Whichpocharacteristicpoappliespotoposolid-
statepodrivespo(SSDs)pocomparedpotopomagneticpodrives?
ApoTheypohaveposlowerpostart-uppotimes.
BpoTheypocostpoless.
CpoTheypoarepolessposusceptiblepotopodamage.
DpoTheypousepomorepopower.po-poans--C
Whichpotypepoofpostoragepoformatposhouldpobepotransportedpoinpoapospecialpobagpotopored
ucepoelectrostaticpointerference?
ApoSolid-statepodrives
BpoMagneticpomedia
CpoDigitalpoaudiopotapes
DpoOpticalpomediapo-poans--B
WhichpoWindowspocomponentpoisporesponsiblepoforporeadingpothepoboot.inipofilepoandpodi
splayingpothepobootpoloaderpomenupoonpoWindowspoXPpoduringpothepobootpoprocess?
ApoWin32posubsystem
BpoNTLDR
CpoNTOSKRNL
DpoWindowspoRegistrypo-poans--B
Thepofollowingpolinepoofpocodepoispoanpoexamplepoofpohowpotopomakepoapoforensicpocopyp
oofpoaposuspectpodrive:ddpoif=/dev/mempoof=/evidence/image.memory1
Whichpooperatingposystemposhouldpobepousedpotoporunpothispocommand?
ApoChrome
BpoBlackBerry
CpoWindows