• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 115 páginas
Examen

CySA+ Final - Study Guide Questions and Answers (2023/2024) (Verified Answers)

Document preview thumbnail
Vista previa 4 fuera de 115 páginas

CySA+ Final - Study Guide Questions and Answers (2023/2024) (Verified Answers)

Vista previa del contenido

CySA+ Final - Study Guide Questions and Answers
(Verified Answers) 2023 - 2024
1.Which format does dd produce files in?
A.ddf
B.RAW
C.EN01
D.OVF>>>>. dd creates files in RAW, bit-by-bit format. EN01 is the EnCase forensic file format, OVF is virtualization file format, and ddf is a made-up answer.
2.Files remnants found in clusters that have been only partially rewritten
by new files found are in what type of space?
A.Outer
B.Slack
C.Unallocated space
D.Non-Euclidean >>>>. Slack space is the space that remains when only a portion of a cluster is used by a file. Data from previous files may remain in the slack space since it is typically not wiped or overwritten. Unallocated space is space on a drive that has not been made into part of a partition. Outer space and non-Euclidean space are
not terms used for filesystems or forensics.
3.Mike is looking for information about files that were changed on a Windows system. Which of the following is least likely to contain useful
information for his investigation?
A.The MFT
B.INDX files
C.Event logs
D.Volume shadow copies >>>>. Event logs do not typically contain significant amounts of information about file changes. The Master File Table and file indexes (INDX files) both have specific information about
files, whereas volume shadow copies can help show differences between files and locations at a point in time.
4.Alice wants to copy a drive without any chance of it being modified by the copying process. What type of device should she use to ensure that this does not happen?
A.read blocker
B.drive cloner
C.write blocker
D.hash validator>>>>. Write blockers ensure that no changes are made to a source drive when creating a forensic copy. Preventing reads would stop you from copying the drive, drive cloners may or may not have write blocking capabilities built in, and hash validation is
useful to ensure contents match but don't stop changes to the source drive from occurring. .Frederick wants to determine if a thumb drive was ever plugged into a Windows system. How can he test for this?
A.Review the MFT
B.Check the system's live memory
C.Use USB Historian
D.Create a forensic image of the drive >>>>. USB Historian provides a
list of devices that are logged in the Windows Registry. Frederick can check the USB device's serial number and other identifying information against the Windows system's historical data. If the device isn't listed, it is not absolute proof, but if it is listed, it is reasonable to assume that it was used on the device.
6.What two files may contain encryption keys normally stored only in mem- ory on a Window system?
A.The MFT and the hash file
B.The Registry and hibernation files
C.Core dumps and encryption logs
D.Core dumps and hibernation files>>>>. Core dumps and hibernation files both contain an image of the live memory of a system, potentially
allowing encryption keys to be retrieved from the stored file. The MFT provides information about file layout, and the Registry contains system information but shouldn't have encryption keys stored in it. There is no hash file or encryption log stored as a Windows default file.
7.Jeff is investigating a system compromise and knows that the first event was reported on October 5th. What forensic tool capability should he
use to map other events found in logs and files to this date? A.timeline
B.log viewer
C.Registry analysis
D.Timestamp validator>>>>. Timelines are one of the most useful tools when conducting an investigation of a compromise or other event. Forensic tools provide built-in timeline capabilities to allow this type of analysis.
8.During her forensic copy validation process Danielle received the
follow- ing MD5 sums from her original drive and the cloned image after
using dd. What is likely wrong?
b49794e007e909c00a51ae208cacb169 original.img
d9ff8a0cf6bc0ab066b6416e7e7abf35 clone.img
A.The original was modified.

Información del documento

Subido en
23 de septiembre de 2023
Número de páginas
115
Escrito en
2023/2024
Tipo
Examen
Contiene
Preguntas y respuestas
$10.59

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
LectWilson
4.5
(8)
Vendido
39
Seguidores
23
Artículos
509
Última venta
2 meses hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes