問題1
Why should you never power on a computer that you need to acquire digital evidence from?
Why should you never power on a computer that you need to acquire digital evidence from?
正確答案: A
問題2
In a Linux-based system, what does the command "Last -F" display?
In a Linux-based system, what does the command "Last -F" display?
正確答案: A
問題3
Which layer of iOS architecture should a forensics investigator evaluate to analyze services such as Threading, File Access, Preferences, Networking and high-level features?
Which layer of iOS architecture should a forensics investigator evaluate to analyze services such as Threading, File Access, Preferences, Networking and high-level features?
正確答案: B
問題4
What is the location of the binary files required for the functioning of the OS in a Linux system?
What is the location of the binary files required for the functioning of the OS in a Linux system?
正確答案: D
問題5
When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:
When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:
正確答案: B
問題6
An investigator has acquired packed software and needed to analyze it for the presence of malice. Which of the following tools can help in finding the packaging software used?
An investigator has acquired packed software and needed to analyze it for the presence of malice. Which of the following tools can help in finding the packaging software used?
正確答案: A
問題7
Bob works as information security analyst for a big finance company. One day, the anomaly-based intrusion detection system alerted that a volumetric DDOS targeting the main IP of the main web server was occurring.
What kind of attack is it?
Bob works as information security analyst for a big finance company. One day, the anomaly-based intrusion detection system alerted that a volumetric DDOS targeting the main IP of the main web server was occurring.
What kind of attack is it?
正確答案: D
問題8
Which of the following is a precomputed table containing word lists like dictionary files and brute force lists and their hash values?
Which of the following is a precomputed table containing word lists like dictionary files and brute force lists and their hash values?
正確答案: B
問題9
Analyze the hex representation of mysql-bin.000013 file in the screenshot below. Which of the following will be an inference from this analysis?

Analyze the hex representation of mysql-bin.000013 file in the screenshot below. Which of the following will be an inference from this analysis?

正確答案: B
問題10
Profiling is a forensics technique for analyzing evidence with the goal of identifying the perpetrator from their various activity. After a computer has been compromised by a hacker, which of the following would be most important in forming a profile of the incident?
Profiling is a forensics technique for analyzing evidence with the goal of identifying the perpetrator from their various activity. After a computer has been compromised by a hacker, which of the following would be most important in forming a profile of the incident?
正確答案: B
問題11
Where should the investigator look for the Edge browser's browsing records, including history, cache, and cookies?
Where should the investigator look for the Edge browser's browsing records, including history, cache, and cookies?
正確答案: D
問題12
What feature of Decryption Collection allows an investigator to crack a password as quickly as possible?
What feature of Decryption Collection allows an investigator to crack a password as quickly as possible?
正確答案: C
問題13
What must be obtained before an investigation is carried out at a location?
What must be obtained before an investigation is carried out at a location?
正確答案: B
問題14
When monitoring for both intrusion and security events between multiple computers, it is essential that the computers ' clocks are synchronized. Synchronized time allows an administrator to reconstruct what took place during an attack against multiple computers. Without synchronized time, it is very difficult to determine exactly when specific events took place, and how events interlace. What is the name of the service used to synchronize time among multiple computers?
When monitoring for both intrusion and security events between multiple computers, it is essential that the computers ' clocks are synchronized. Synchronized time allows an administrator to reconstruct what took place during an attack against multiple computers. Without synchronized time, it is very difficult to determine exactly when specific events took place, and how events interlace. What is the name of the service used to synchronize time among multiple computers?
正確答案: C