• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 9 pages
Exam (elaborations)

DFIR (Digital Forensics and Incident Response) – Exam Prep Study Guide – Verified Questions and Answers

Document preview thumbnail
Preview 2 out of 9 pages

This document serves as a focused exam preparation guide for DFIR, featuring a wide range of verified multiple-choice questions and definitions. Key areas include memory forensics, data carving, network analysis, malware persistence techniques, sandboxing, steganography, CPU architectures, and incident response roles and phases (NIST, RACI). Tools and terms like FTK Imager, Volatility, UPX, PEiD, Bulk Extractor, and Rekall are clearly explained. Ideal for students and professionals preparing for certification.

Content preview

DFIR Exam Prep questions with accurate
answers
A task can be set to run a malicious payload upon system boot. This type
of Persistence technique is called? Ans✓✓✓Scheduled task


Actions performed after an incident, including collecting data left behind
by an intrusion (artifacts), preserving the data for future use as evidence,
and studying what can be learned from the incident to improve
Cybersecurity against future events. Is all part of? Ans✓✓✓Post
incident activities


After you enter a website, a pop-up appears saying your computer files
were infected, and offering to fix the problem for a small fee. Which of
the following attacks did you encounter? Ans✓✓✓Scareware


Containment, eradication, and recovery steps in the NIST is defined as?
Ans✓✓✓Taking action to mitigate the incident.


Depending on the location of the capture, Wireshark can provide a tool
to transfer some objects such as files over the network. What Wireshark
feature is available to do this? Ans✓✓✓Export


Determining if an incident occurred, and what type of incident it was.
Ans✓✓✓Detection and analysis

, Hackers can encrypt static data to avoid detection. This type of
obfuscation is called? Ans✓✓✓Encryption


Hackers can hide crucial information in existing files. This type of
obfuscation is called? Ans✓✓✓Stegnography


Hackers can hide information in network traffic. This type of
obfuscation is called? Ans✓✓✓Tunneling


In Wireshark, filters are powerful tools that can be used to narrow
searches for a specific goal. For example, if you are looking only for
outbound HTTP traffic, you could use the following:
src host x.x.x.x & http
(where x.x.x.x is your IP address) Name the Wireshark Feature?
Ans✓✓✓Display Filter Expressions


John opened an executable file and noticed unusual activity, such as files
that opened on their own. For further investigation, he wanted to check
if any new network connections were established. Which of the
following tools can check network connections? Ans✓✓✓Netstat


John was tasked to investigate a network attack in accordance with the
network forensics investigation flow process. What should be John's first
step? Ans✓✓✓Check for malware signatures

Document information

Uploaded on
June 26, 2025
Number of pages
9
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions