Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 8 páginas
Examen

DFCS 635 (DFCS635) unit 1 and 2 quizzes | questions and answers - latest 100% correct Winter 26 - UMGC.

Document preview thumbnail
Vista previa 2 fuera de 8 páginas

DFCS 635 (DFCS635) unit 1 and 2 quizzes Unit 1 Quiz Question 1 (1 point) Which step is not one of the five steps of the NIST Framework? Question 1 options: Detect Identify Protect Recover Execute Question 2 (1 point) What is NOT a motivation for cyber threat actors? Question 2 options: Espionage Political Tampering Financial Gain System Optimization Question 3 (1 point) Which is NOT one of the six steps of the CVE process? Question 3 options: Record Publish Discover Request Submit ReserveQuestion 4 (1 point) What is MITRE ATT&CK? Question 4 options: MITRE ATT&CK is a high-performance computing environment run by MITRE. MITRE ATT&CK is a virtualization platform for running container images. MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations of cyberattacks. MITRE ATT&CK is an application executed to compromise vulnerable systems. Question 5 (1 point) MITRE creates or manages processes for all of the following, with the exception of what? Question 5 options: CVEs APTs ATT&CK CAR Question 6 (1 point) How can previous incident reports provide intelligence data when operationalizing MITRE ATT&CK? Question 6 options: By providing an analytical model for the blue team By providing a scope of work during purple teaming exercises By mapping the behaviors to tactics and technique By providing the red team with a templateQuestion 7 (1 point) All of the following are sources of data collection except for what? Question 7 options: Incident response reports File and registry monitoring Authentication logs collected from the domain controller Process and process command line monitoring Question 8 (1 point) These are specific implementations of how the adversary’s technical goals are achieved. Question 8 options: Tools Procedures Tactics Techniques Question 9 (1 point) This ATT&CK tactic results in adversary-controlled code running on a local or remote system. Question 9 options: Execution Initial access Privilege escalation Lateral movementQuestion 10 (1 point) TTPs describe actions taken by adversaries during a network attack. Question 10 options: True FalseUNIT 2 QUIZ Question 1 (1 point) What is a forensic image collection technique that captures all files that are visible to the user (but not lost or deleted items)? Question 1 options: None of the above A physical device collection A logical image of a device A target collection Question 2 (1 point) How does virtualization provide preservation? Question 2 options: Virtualization allows you to reset the machine image after each inspection change. A virtual machine ensures the original device remains untouched. A virtual machine doesn't provide any preservation capabilities. A virtual machine can be stored on a thumb drive for transport and safe keeping. Question 3 (1 point) What is the chain of custody? Question 3 options: The list of all employees of the crime lab A log of everyone who has read about the digitally collected evidence A documentation process that protects evidence from contamination and tampering and preserves evidence integrity A list of every artifact of evidence collectedQuestion 4 (1 point) What are type 1 hypervisors installed on? Question 4 options: USB drives and other detachable external media Customized machines built in the cloud A host operating system Bare metal systems allowing direct access to interact with hardware Question 5 (1 point) What is a forensic image collection technique that is constrained to a specific focus? Question 5 options: None of the above A target collection A physical device collection A logical image of a device Question 6 (1 point) What is a core advantage of using virtual machines for forensic investigation? Question 6 options: Isolation of forensic environments from the host system Integration of multiple operating systems into a single environment Ability to run games and graphics-intensive applications Access to a faster internet connectionQuestion 7 (1 point) What is a forensic image collection technique that is a bit-by-bit copy of the equipment? Question 7 options: A target collection A physical device collection A logical image of a device None of the above Question 8 (1 point) What does virtual machine isolation mean? Question 8 options: Virtual machines can only be accessed locally. Virtual machines run independently and are isolated from each other and the host system. Virtual machines share the same resources and cannot be isolated. Virtual machines can communicate directly with the physical hardware. Question 9 (1 point) What is the primary purpose of a hypervisor in virtualization? Question 9 options: To allocate hardware resources and manage virtual machines To create virtual hard disks To manage the network connections To manage the guest operating systemsQuestion 10 (1 point) What is the benefit for anti-forensics of virtual machine portability? Question 10 options: It reduces the need for hardware virtualization. It allows virtual machines to communicate with each other easily. It ensures faster boot times for virtual machines. It allows virtual machines to be moved between different physical machines with compatible hypervisors.

Vista previa del contenido

Unit 1 Quiz


Question 1 (1 point)

Which step is not one of the five steps of the NIST Framework?
Question 1 options:
Detect
Identify
Protect
Recover
Execute


Question 2 (1 point)

What is NOT a motivation for cyber threat actors?
Question 2 options:
Espionage
Political Tampering
Financial Gain
System Optimization


Question 3 (1 point)

Which is NOT one of the six steps of the CVE process?
Question 3 options:
Record
Publish
Discover
Request
Submit
Reserve

, Question 4 (1 point)

What is MITRE ATT&CK?
Question 4 options:
MITRE ATT&CK is a high-performance computing environment run by MITRE.
MITRE ATT&CK is a virtualization platform for running container images.
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on
real-world observations of cyberattacks.
MITRE ATT&CK is an application executed to compromise vulnerable systems.


Question 5 (1 point)

MITRE creates or manages processes for all of the following, with the
exception of what?
Question 5 options:
CVEs
APTs
ATT&CK
CAR


Question 6 (1 point)

How can previous incident reports provide intelligence data when
operationalizing MITRE ATT&CK?
Question 6 options:
By providing an analytical model for the blue team
By providing a scope of work during purple teaming exercises
By mapping the behaviors to tactics and technique
By providing the red team with a template

Información del documento

Subido en
13 de mayo de 2026
Número de páginas
8
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$16.39

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
MindCraft
3.8
(47)
Vendido
368
Seguidores
7
Artículos
2789
Última venta
4 horas hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes