100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

DFIR - DIGITAL FORENSICS INCIDENT TRAINING UPDATED QUESTIONS AND ANSWERS

Rating
-
Sold
-
Pages
9
Grade
A+
Uploaded on
07-05-2025
Written in
2024/2025

DFIR - DIGITAL FORENSICS INCIDENT TRAINING UPDATED QUESTIONS AND ANSWERS Hot site - CORRECT ANSWERA backup that is running continuously and ready for imediate switchover

Institution
DFIR
Course
DFIR









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
DFIR
Course
DFIR

Document information

Uploaded on
May 7, 2025
Number of pages
9
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

  • dfir

Content preview

DFIR - DIGITAL FORENSICS INCIDENT TRAINING UPDATED
QUESTIONS AND ANSWERS
Hot site - CORRECT ANSWER✅✅✅A backup that is running continuously and ready for imediate
switchover



warm site - CORRECT ANSWER✅✅✅Servers & other resources for backup but not as ready for
switchover



cold site - CORRECT ANSWER✅✅✅Cheapest backup option does not always have the necessary
equipment to enable the resumption of normal operation



Connscan - CORRECT ANSWER✅✅✅Scans for identifiable TCP connections in older versions of
Windows



Sockets - CORRECT ANSWER✅✅✅Scans for all our sockets



NetScan - CORRECT ANSWER✅✅✅Can be used in more recent versions of Windows



Conscan should be used as a complimentary plugin with - CORRECT ANSWER✅✅✅Sockets



Static Binaries - CORRECT ANSWER✅✅✅use a minimal footprint on the system as they are not
dependent on libraries pre-install on the Linux OS. & Doesn't require other files to run



Where can Linux logs be found? - CORRECT ANSWER✅✅✅/var/log



Where can you view Windows logs? - CORRECT ANSWER✅✅✅Event Viewer



What is that thing where Splunk finds related events? - CORRECT ANSWER✅✅✅Correlation

, How are vulvectomies tracked? - CORRECT ANSWER✅✅✅By a CVE number



What should you focus on when threat hunting? - CORRECT ANSWER✅✅✅Anomalies



What is the purpose of intelligence? - CORRECT ANSWER✅✅✅To provide an advantage over your
adversary



Zeek is a tool for... - CORRECT ANSWER✅✅✅Analyzing network traffic



UBA, User behavior analytics knows what "normal " is for each user? - CORRECT ANSWER✅✅✅True



Where does fileless malware get stored? - CORRECT ANSWER✅✅✅It doesn't



Which does NOT contain memory artifacts that can be analyzed? - CORRECT ANSWER✅✅✅RAM
disk



What contains memory artifacts that can be analyzed? - CORRECT ANSWER✅✅✅- Crash dump file

- Page file

- Hibernation file



When inspecting processes we look at all of the following: - CORRECT ANSWER✅✅✅- parent
process

- network connections

- DLLs used



What do we not look for when inspecting processes? - CORRECT ANSWER✅✅✅Process size



You can recover a computer's RAM only when it is turned .. - CORRECT ANSWER✅✅✅Off

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STANGRADES Stanford University
View profile
Follow You need to be logged in order to follow users or courses
Sold
51
Member since
1 year
Number of followers
1
Documents
10091
Last sold
4 days ago
STAN-GRADES

EXCELLENCY IN ACADEMIC MATERIALS

3.4

11 reviews

5
4
4
1
3
3
2
1
1
2

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions