WGUlD431lObjectivelAssessmentlGuidel
(NewlUpdate)lDigitallForensicslin
lCybersecurity|lQsl&lAs|lGradelAl100%
lCorrectl(VerifiedlAnswers)
QUESTION
Thelchieflinformationlsecuritylofficerloflalcompanylbelieveslthatlanlattackerlhaslinfiltratedlthel
company'slnetworklandlislusinglsteganographyltolcommunicatelwithlexternallsources.lAlsecurit
ylteamlislinvestigatinglthelincident.lTheylareltoldltolstartlbylfocusinglonlthelcorelelementsloflst
eganography.lWhatlarelthelcorelelementsloflsteganography?
Answer:
Payload,lcarrier,lchannel
QUESTION
Alsystemladministratorlbelievesldatalarelbeinglleakedlfromlthelorganization.lTheladministratorl
decidesltoluselsteganographyltolhideltrackinglinformationlinltheltypesloflfileslhelthinkslarelbein
glleaked.lWhichlsteganographicltermldescribeslthisltrackinglinformation?
Answer:
Payload
QUESTION
Alcriminallorganizationlhaslcompromisedlalthird-
partylweblserverlandlislusinglitltolcontrollalbotnet.lThelbotnetlserverlhideslcommandlandlcontr
ollmessageslthroughlthelDNSlprotocol.lWhichlsteganographiclcomponentlarelthelcommandland
lcontrollmessages?
,Answer:
Payload
QUESTION
Whichlmethodlislcommonlylusedltolhideldatalvialsteganography?
Answer:
LSB
QUESTION
Alsystemladministratorlbelieveslanlemployeelislleakinglinformationltolalcompetitorlbylhidinglc
onfidentialldatalinlimageslbeinglattachedltoloutgoinglemails.lTheladministratorlhaslcapturedlthe
loutgoinglemails.lWhichltoollshouldlthelforensiclinvestigatorluseltolsearchlforlthelhiddenldatali
nlthelimages?
Answer:
ForensiclToolkitl(FTK)
QUESTION
AlforeignlgovernmentlislcommunicatinglwithlitslagentslinlthelU.S.lbylhidingltextlmessageslinlp
opularlAmericanlsongs,lwhichlareluploadedltolthelweb.lWhichlsteganographicltoollcanlbelusedl
toldolthis?
Answer:
MP3Stego
QUESTION
,Duringlalcyber-
forensicslinvestigation,lalUSBldrivelwaslfoundlthatlcontainedlmultiplelpicturesloflthelsamelflo
wer.lHowlshouldlanlinvestigatorluselpropertiesloflalfileltoldetectlsteganography?
Answer:
Reviewlthelhexadecimallcodellookinglforlanomalieslinlthelfilelheaderslandlendingslusinglaltool
lsuchlaslEnCase.
QUESTION
Foremost
Answer:
Foremostlislalfilelcarvinglutilitylthatlallowslyoultolcarvelfileslthatlwerel"deleted"loutloflaldiskli
magelorlalmountedlpartition.lForemostlwaslcreatedlbylJesselKornblumlandlislavailablelforldow
nloadlfromlthisllink:lhttp://foremost.sourceforge.net/
QUESTION
Hexadecimal
Answer:
Alnumberinglsystemlwherelnumbersl0-9landlletterslA-
Flarelused.lAlsolknownlaslbasel16,lhexadecimallislcommonlylusedlinlcomputerlforensicslandln
etworking.
QUESTION
HEXlEditor
Answer:
AlGraphicallUserlInterfacel(GUI)lorlcommandllineltoollthatlcanlbelutilizedltolanalyzelthelhexa
decimallcodeloflfiles.lFilelheaderslhavelhexadecimallsignatureslthatlareluniqueltolalparticularlty
peloflfile.lForlexample,lalJPEGlfilelhaslalfilelsignatureloflJFIF.
, QUESTION
md5sum
Answer:
AlcommandlthatlislusedlfromlthelterminalltolverifylanlMD5lhash.lMessagelDigestl5lislal128-
bitlhashinglalgorithmlthatlaidslforensiclexaminerslbyl"proving"lthatlthelcopyloflthelmedialtheyl
arelworkinglonlisl"equivalent"ltoltheloriginal.
QUESTION
sha1sum
Answer:
Alcommandlthatlislusedlfromlthelterminalltolverifylalsha1lhash.lSecurelHashlAlgorithmlislal16
0-
bitlhashinglalgorithmlthatlaidslforensiclexaminerslbyl"proving"lthatlthelcopyloflthelmedialtheyl
arelworkinglonlisl"equivalent"ltoltheloriginal.
QUESTION
dd
Answer:
AlUnix/Linuxlprogramlthatlallowslyoultolbackuplmedia.lYoulcanlcreatelalbit-by-
bitlcopylofltheloriginallmedia,lonelthatlislforensicallylequivalentltoltheloriginallsource.
QUESTION
dcfldd
(NewlUpdate)lDigitallForensicslin
lCybersecurity|lQsl&lAs|lGradelAl100%
lCorrectl(VerifiedlAnswers)
QUESTION
Thelchieflinformationlsecuritylofficerloflalcompanylbelieveslthatlanlattackerlhaslinfiltratedlthel
company'slnetworklandlislusinglsteganographyltolcommunicatelwithlexternallsources.lAlsecurit
ylteamlislinvestigatinglthelincident.lTheylareltoldltolstartlbylfocusinglonlthelcorelelementsloflst
eganography.lWhatlarelthelcorelelementsloflsteganography?
Answer:
Payload,lcarrier,lchannel
QUESTION
Alsystemladministratorlbelievesldatalarelbeinglleakedlfromlthelorganization.lTheladministratorl
decidesltoluselsteganographyltolhideltrackinglinformationlinltheltypesloflfileslhelthinkslarelbein
glleaked.lWhichlsteganographicltermldescribeslthisltrackinglinformation?
Answer:
Payload
QUESTION
Alcriminallorganizationlhaslcompromisedlalthird-
partylweblserverlandlislusinglitltolcontrollalbotnet.lThelbotnetlserverlhideslcommandlandlcontr
ollmessageslthroughlthelDNSlprotocol.lWhichlsteganographiclcomponentlarelthelcommandland
lcontrollmessages?
,Answer:
Payload
QUESTION
Whichlmethodlislcommonlylusedltolhideldatalvialsteganography?
Answer:
LSB
QUESTION
Alsystemladministratorlbelieveslanlemployeelislleakinglinformationltolalcompetitorlbylhidinglc
onfidentialldatalinlimageslbeinglattachedltoloutgoinglemails.lTheladministratorlhaslcapturedlthe
loutgoinglemails.lWhichltoollshouldlthelforensiclinvestigatorluseltolsearchlforlthelhiddenldatali
nlthelimages?
Answer:
ForensiclToolkitl(FTK)
QUESTION
AlforeignlgovernmentlislcommunicatinglwithlitslagentslinlthelU.S.lbylhidingltextlmessageslinlp
opularlAmericanlsongs,lwhichlareluploadedltolthelweb.lWhichlsteganographicltoollcanlbelusedl
toldolthis?
Answer:
MP3Stego
QUESTION
,Duringlalcyber-
forensicslinvestigation,lalUSBldrivelwaslfoundlthatlcontainedlmultiplelpicturesloflthelsamelflo
wer.lHowlshouldlanlinvestigatorluselpropertiesloflalfileltoldetectlsteganography?
Answer:
Reviewlthelhexadecimallcodellookinglforlanomalieslinlthelfilelheaderslandlendingslusinglaltool
lsuchlaslEnCase.
QUESTION
Foremost
Answer:
Foremostlislalfilelcarvinglutilitylthatlallowslyoultolcarvelfileslthatlwerel"deleted"loutloflaldiskli
magelorlalmountedlpartition.lForemostlwaslcreatedlbylJesselKornblumlandlislavailablelforldow
nloadlfromlthisllink:lhttp://foremost.sourceforge.net/
QUESTION
Hexadecimal
Answer:
Alnumberinglsystemlwherelnumbersl0-9landlletterslA-
Flarelused.lAlsolknownlaslbasel16,lhexadecimallislcommonlylusedlinlcomputerlforensicslandln
etworking.
QUESTION
HEXlEditor
Answer:
AlGraphicallUserlInterfacel(GUI)lorlcommandllineltoollthatlcanlbelutilizedltolanalyzelthelhexa
decimallcodeloflfiles.lFilelheaderslhavelhexadecimallsignatureslthatlareluniqueltolalparticularlty
peloflfile.lForlexample,lalJPEGlfilelhaslalfilelsignatureloflJFIF.
, QUESTION
md5sum
Answer:
AlcommandlthatlislusedlfromlthelterminalltolverifylanlMD5lhash.lMessagelDigestl5lislal128-
bitlhashinglalgorithmlthatlaidslforensiclexaminerslbyl"proving"lthatlthelcopyloflthelmedialtheyl
arelworkinglonlisl"equivalent"ltoltheloriginal.
QUESTION
sha1sum
Answer:
Alcommandlthatlislusedlfromlthelterminalltolverifylalsha1lhash.lSecurelHashlAlgorithmlislal16
0-
bitlhashinglalgorithmlthatlaidslforensiclexaminerslbyl"proving"lthatlthelcopyloflthelmedialtheyl
arelworkinglonlisl"equivalent"ltoltheloriginal.
QUESTION
dd
Answer:
AlUnix/Linuxlprogramlthatlallowslyoultolbackuplmedia.lYoulcanlcreatelalbit-by-
bitlcopylofltheloriginallmedia,lonelthatlislforensicallylequivalentltoltheloriginallsource.
QUESTION
dcfldd