• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 26 pages
Exam (elaborations)

Incident Response – Exam 3 Study Guide with Accurate Answers (Disaster Recovery & Forensics)

Document preview thumbnail
Preview 3 out of 26 pages

This document presents a detailed study guide for Exam 3 in incident response, covering essential concepts in disaster recovery, digital forensics, business continuity planning, and forensic readiness. Includes a mix of multiple-choice, true/false, and open-ended questions with verified answers. Topics include phases of a DR plan, CSIRT roles, forensic techniques, containment strategies, and legal standards relevant to forensic investigation and data privacy.

Content preview

Incident response Exam 3 study guide questions
with accurate answers
____ disasters include acts of terrorism and acts of war. Ans✓✓✓Man-
made


____ incidents are predominantly characterized as a violation of policy
rather than an effort to abuse existing systems. Ans✓✓✓Inappropriate
use


____ involves an attempt made by those who may become subject to
digital forensic techniques to obfuscate or hide items of evidentiary
value. Ans✓✓✓Anti-forensics


____ may be caused by earthquakes, floods, storm winds, tornadoes, or
mud flows. Ans✓✓✓. Rapid onset disasters


____ means making an organization ready for possible contingencies
that can escalate to become disasters. Ans✓✓✓Preparation


____________________ is a category of incidents that covers a
spectrum of violations made by authorized users of a system who
nevertheless use the system in ways specifically prohibited by
management. Ans✓✓✓Inappropriate Use (IU)


____________________ testing can come from standardization boards
or consultants (for example, ISO 9000), certification or accreditation

,groups, or a group selected by the organization's management from a
sister company. Ans✓✓✓External


____________________ testing can include employees conducting self-
assessments after an exercise by completing feedback surveys indicating
what they thought worked well and what did not. Ans✓✓✓Internal


______________________________ is the preparation for and recovery
from a disaster, whether natural or man-made. Ans✓✓✓Disaster
recovery planning


A ____ is a small quantity of data kept by a Web site as a means of
recording that a system has visited that Web site. Ans✓✓✓cookie


A business continuity plan should be a single unified plan.
Ans✓✓✓False


A certification offered by the Business Continuity Institute is called
____. Ans✓✓✓BCI Professional Recognition Program


A continuously changing process presents challenges in acquisition, as
there is not a fixed state that can be collected, hashed, and so forth. This
has given rise to the concept of ____ forensics which captures a point-
in-time picture of a process. Ans✓✓✓snapshot

, A DR plan addendum should include the trigger, the ____ method, and
the response time associated with each disaster situation.
Ans✓✓✓notification


A forensics team typically uses two methods to document a scene as it
exists at the time of arrival: photography and ____. Ans✓✓✓field notes


A search is constitutional if it does not violate a person's reasonable or
legitimate____. Ans✓✓✓expectation of privacy


A search that is constrained to a specific focus Ans✓✓✓Permissible in
scope


An ____ may escalate into a disaster when it grows in scope and
intensity. Ans✓✓✓incident


An increasing concern for privacy and widespread availability of
encryption products has led to the use of encryption for individual files
and even entire devices. Briefly discuss the current state of encryption
with respect to forensic investigation. Ans✓✓✓Although some
encryption is poorly done and is easily broken, high-quality products are
increasingly available that use good encryption algorithms beyond our
current capability to reverse encryption by trying all possible
combinations. Encrypted information poses significant challenges to
forensic investigators because, by its nature, encryption conceals the
content of digital material. Many encryption products require input of an
encryption key when the user logs on and then decrypts the user's
information on the fly. When the system goes into screen saver mode or

Document information

Uploaded on
June 26, 2025
Number of pages
26
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$19.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions