Computer Hacking Forensic Investigator Certification Test! Trivia Quiz

Approved & Edited by ProProfs Editorial Team
The editorial team at ProProfs Quizzes consists of a select group of subject experts, trivia writers, and quiz masters who have authored over 10,000 quizzes taken by more than 100 million users. This team includes our in-house seasoned quiz moderators and subject matter experts. Our editorial experts, spread across the world, are rigorously trained using our comprehensive guidelines to ensure that you receive the highest quality quizzes.
Learn about Our Editorial Process
| By Dale
D
Dale
Community Contributor
Quizzes Created: 6 | Total Attempts: 4,187
Questions: 50 | Attempts: 446

SettingsSettingsSettings
Computer Hacking Forensic Investigator Certification Test! Trivia Quiz - Quiz

Are you preparing to sit for the computer hacking forensic investigator certification test? Getting access to people's networks and data is a very tedious thing is you do not know what you are doing, and this is why the hacking certificate is not given to just anyone. Do take up the quiz and get to see only how prepared you are for the exam.


Questions and Answers
  • 1. 

    What file structure database would you expect to find on floppy disks?

    • A.

      NTFS

    • B.

      FAT32

    • C.

      FAT16

    • D.

      FAT12

    Correct Answer
    D. FAT12
    Explanation
    Floppy disks were commonly used in the past for storing data. The FAT12 file structure database is the most suitable for floppy disks because it is specifically designed for small storage devices. FAT12 uses a 12-bit file allocation table and is capable of managing the limited storage capacity of floppy disks efficiently. Therefore, it is expected to find the FAT12 file structure database on floppy disks.

    Rate this question:

  • 2. 

    What type of attack occurs when an attacker can force a router to stop forwarding packets by flooding the router with many open connections simultaneously so that all the hosts behind the router are effectively disabled?

    • A.

      Digital Attack

    • B.

      Denial-of-Service (DoS)

    • C.

      Physical Attack

    • D.

      ARP Redirect

    Correct Answer
    B. Denial-of-Service (DoS)
    Explanation
    A denial-of-service (DoS) attack occurs when an attacker floods a router with numerous open connections simultaneously, causing the router to stop forwarding packets. This flood of connections overwhelms the router's resources, rendering it unable to function properly. As a result, all the hosts behind the router are effectively disabled and unable to communicate with the network. This type of attack aims to disrupt the availability of a network or service by overwhelming its resources and causing it to become unresponsive.

    Rate this question:

  • 3. 

    When examining a file with a Hex Editor, what space does the file header occupy?

    • A.

      The last several bytes of the file

    • B.

      The first several bytes of the file

    • C.

      None, file headers are contained in the FAT

    • D.

      One byte at the beginning of the file

    Correct Answer
    D. One byte at the beginning of the file
    Explanation
    The file header occupies one byte at the beginning of the file. This byte is used to store information about the file, such as its format or type. It is typically the first piece of data that is read when opening a file and is important for identifying and interpreting the contents of the file.

    Rate this question:

  • 4. 

    In the context of the file deletion process, which of the following statements holds TRUE?

    • A.

      When files are deleted, the data is overwritten and the cluster marked as available

    • B.

      The longer a disk is in use, the less likely it is that deleted files will be overwritten

    • C.

      While booting, the machine may create temporary files that can delete evidence

    • D.

      Secure delete programs work by completely overwriting the file in one go

    Correct Answer
    C. While booting, the machine may create temporary files that can delete evidence
    Explanation
    While booting, the machine may create temporary files that can delete evidence. This statement is true because during the booting process, temporary files are often created by the operating system or other programs. These temporary files can potentially overwrite or delete evidence of previously deleted files, making it harder to recover them. This is why it is important to use specialized tools and techniques for data recovery if the deleted files are of importance.

    Rate this question:

  • 5. 

    A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache. Moreover, he has removed any images he might have downloaded. What can the investigator do to prove the violation?

    • A.

      Image the disk and try to recover deleted files

    • B.

      Seek the help of co-workers who are eye-witnesses

    • C.

      Check the Windows registry for connection data (you may or may not recover)

    • D.

      Approach the websites for evidence

    Correct Answer
    A. Image the disk and try to recover deleted files
    Explanation
    The correct answer is to image the disk and try to recover deleted files. By creating a forensic image of the suspect's disk, the investigator can make an exact copy of the data stored on it. This allows them to conduct a thorough analysis of the disk without altering or tampering with the original evidence. By using specialized forensic tools, the investigator can attempt to recover deleted files, including browsing history, cookies, and downloaded images, which can provide evidence of the suspect's activities on adult websites.

    Rate this question:

  • 6. 

    A ________________ is one whereby by a computer program rather than a hacker performs the steps in the attack sequence.

    • A.

      Blackout attack

    • B.

      Automated attack

    • C.

      Distributed attack

    • D.

      Central processing attack

    Correct Answer
    B. Automated attack
    Explanation
    An automated attack refers to a type of attack where a computer program, rather than a hacker, carries out the steps in the attack sequence. This means that the attack is executed automatically, without the need for human intervention. In an automated attack, the program can be designed to exploit vulnerabilities, launch malicious actions, or gain unauthorized access to systems or networks. This type of attack is often used to target multiple systems simultaneously and can be highly efficient and difficult to detect.

    Rate this question:

  • 7. 

    The offset in a hexadecimal code is:

    • A.

      The last byte after the colon

    • B.

      The 0x at the beginning of the code

    • C.

      The 0x at the end of the code

    • D.

      The first byte after the colon

    Correct Answer
    B. The 0x at the beginning of the code
    Explanation
    The 0x at the beginning of the code is the offset in a hexadecimal code. Hexadecimal codes often start with 0x to indicate that the following characters represent a hexadecimal value. This allows the code reader to interpret the value correctly. The offset represents the position or location of a specific byte within the code, and in this case, it is indicated by the 0x at the beginning.

    Rate this question:

  • 8. 

    It takes _____________ mismanaged case/s to ruin your professional reputation as a computer forensics examiner?

    • A.

      By law, three

    • B.

      Quite a few

    • C.

      Only one

    • D.

      At least two

    Correct Answer
    C. Only one
    Explanation
    It only takes one mismanaged case to ruin your professional reputation as a computer forensics examiner. This suggests that even a single instance of mishandling a case can have severe consequences and negatively impact the examiner's reputation. It emphasizes the importance of maintaining a high level of professionalism and accuracy in this field.

    Rate this question:

  • 9. 

    With the standard Linux second extended file system (Ext2FS), a file is deleted when the inode internal link count reaches ________.

    • A.

      0

    • B.

      10

    • C.

      100

    • D.

      1

    Correct Answer
    A. 0
    Explanation
    In the standard Linux second extended file system (Ext2FS), the inode internal link count represents the number of hard links pointing to a file. When this count reaches 0, it means that there are no more hard links pointing to the file, indicating that the file is no longer being referenced or used. Therefore, the file is considered deleted.

    Rate this question:

  • 10. 

    When examining the log files from a Windows IIS Web Server, how often is a new log file created?

    • A.

      The same log is used at all times

    • B.

      A new log file is created everyday

    • C.

      A new log file is created each week

    • D.

      A new log is created each time the Web Server is started

    Correct Answer
    A. The same log is used at all times
    Explanation
    In this scenario, the correct answer is "the same log is used at all times". This means that the Windows IIS Web Server does not create a new log file on a regular basis. Instead, it continues to use the same log file for all the server activities. This can be advantageous for tracking and analyzing server events as all the information is stored in a single log file, making it easier to manage and review the server's activity history.

    Rate this question:

  • 11. 

    Which part of the Windows Registry contains the user's password file?

    • A.

      HKEY_LOCAL_MACHINE

    • B.

      HKEY_CURRENT_CONFIGURATION

    • C.

      HKEY_USER

    • D.

      HKEY_CURRENT_USER

    Correct Answer
    A. HKEY_LOCAL_MACHINE
    Explanation
    The correct answer is HKEY_LOCAL_MACHINE. This part of the Windows Registry contains system-wide configuration settings and information for all users on the computer. It does not specifically contain the user's password file.

    Rate this question:

  • 12. 

    An employee is attempting to wipe out data stored on a couple of compact discs (CDs) and digital video discs (DVDs) by using a large magnet. You inform him that this method will not be effective in wiping out the data because CDs and DVDs are ______________ media used to store large amounts of data and are not affected by the magnet.

    • A.

      Logical

    • B.

      Anti-magnetic

    • C.

      Magnetic

    • D.

      Optical

    Correct Answer
    D. Optical
    Explanation
    CDs and DVDs are optical media used to store large amounts of data. Optical media use a laser to read and write data, and the data is stored as microscopic pits on the surface of the disc. The magnet does not affect the data stored on optical media because it does not interfere with the microscopic pits or the laser reading mechanism. Therefore, using a magnet to wipe out the data on CDs and DVDs will not be effective.

    Rate this question:

  • 13. 

    Lance wants to place a honeypot on his network. Which of the following would be your recommendations?

    • A.

      Use a system that has a dynamic addressing on the network

    • B.

      Use a system that is not directly interacting with the router

    • C.

      Use it on a system in an external DMZ in front of the firewall

    • D.

      It doesn't matter as all replies are faked

    Correct Answer
    D. It doesn't matter as all replies are faked
    Explanation
    The correct answer is "It doesn't matter as all replies are faked." This means that regardless of the specific recommendations given, all responses received from the honeypot will be false or manipulated. Therefore, the specific characteristics of the system, such as dynamic addressing or placement in a DMZ, do not have any impact on the faked replies.

    Rate this question:

  • 14. 

    What does the acronym POST mean as it relates to a PC?

    • A.

      Primary Operations Short Test

    • B.

      Power-On Self Test

    • C.

      Pre-Operational Situation Test

    • D.

      Primary Operating System Test

    Correct Answer
    B. Power-On Self Test
    Explanation
    The acronym POST stands for Power-On Self Test. This test is performed by a computer when it is powered on to check if all the hardware components are functioning properly. It helps to identify any potential issues or errors that may prevent the computer from booting up successfully. The Power-On Self Test is an essential part of the boot process and ensures that the computer is in a suitable state to start the operating system.

    Rate this question:

  • 15. 

    E-mail logs contain which of the following information to help you in your investigation? (Choose four.)

    • A.

      User account that was used to send the account

    • B.

      Attachments sent with the e-mail message

    • C.

      Unique message identifier

    • D.

      Contents of the e-mail message

    • E.

      Date and time the message was sent

    Correct Answer(s)
    A. User account that was used to send the account
    C. Unique message identifier
    D. Contents of the e-mail message
    E. Date and time the message was sent
    Explanation
    E-mail logs contain information such as the user account that was used to send the email, the unique message identifier, the contents of the email message, and the date and time the message was sent. These details can be helpful in an investigation as they can provide information about the sender, the specific email being investigated, its content, and when it was sent. By analyzing these logs, investigators can gather evidence and track the source of the email.

    Rate this question:

  • 16. 

    In a forensic examination of hard drives for digital evidence, what type of user is most likely to have the most file slack to analyze?

    • A.

      One who has NTFS 4 or 5 partitions

    • B.

      One who uses dynamic swap file capability

    • C.

      One who uses hard disk writes on IRQ 13 and 21

    • D.

      One who has lots of allocation units per block or cluster

    Correct Answer
    D. One who has lots of allocation units per block or cluster
    Explanation
    The file slack refers to the unused space between the end of a file and the end of the last allocated cluster. The more allocation units per block or cluster a user has, the larger the file slack will be. Therefore, a user who has lots of allocation units per block or cluster is most likely to have the most file slack to analyze in a forensic examination of hard drives for digital evidence.

    Rate this question:

  • 17. 

    In what way do the procedures for dealing with evidence in a criminal case differ from the procedures for dealing with evidence in a civil case?

    • A.

      Evidence must be handled in the same way regardless of the type of case

    • B.

      Evidence procedures are not important unless you work for a law enforcement agency

    • C.

      Evidence in a criminal case must be secured more tightly than in a civil case

    • D.

      Evidence in a civil case must be secured more tightly than in a criminal case

    Correct Answer
    C. Evidence in a criminal case must be secured more tightly than in a civil case
    Explanation
    In a criminal case, the evidence must be secured more tightly than in a civil case. This is because a criminal case involves the accusation of a crime, which can result in the loss of liberty for the accused. Therefore, the evidence needs to be handled with utmost care and security to ensure its integrity and prevent tampering or contamination. In contrast, a civil case typically involves disputes between individuals or organizations, where the consequences are generally limited to monetary compensation. Hence, the level of security for evidence in a civil case is comparatively lower.

    Rate this question:

  • 18. 

    You are assigned to work in the computer forensics lab of a state police agency. While working on a high profile criminal case, you have followed every applicable procedure, however your boss is still concerned that the defense attorney might question whether evidence has been changed while at the lab. What can you do to prove that the evidence is the same as it was when it first entered the lab?

    • A.

      Make an MD5 hash of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab

    • B.

      Make an MD5 hash of the evidence and compare it to the standard database developed by NIST

    • C.

      There is no reason to worry about this possible claim because state labs are certified

    • D.

      Sign a statement attesting that the evidence is the same as it was when it entered the lab

    Correct Answer
    A. Make an MD5 hash of the evidence and compare it with the original MD5 hash that was taken when the evidence first entered the lab
    Explanation
    To prove that the evidence is the same as it was when it first entered the lab, making an MD5 hash of the evidence and comparing it with the original MD5 hash is the most effective method. MD5 is a cryptographic algorithm that generates a unique hash value for a given input. By comparing the MD5 hash of the evidence with the original hash, any changes or tampering with the evidence can be easily detected. This ensures the integrity and authenticity of the evidence, providing a strong defense against any claims of alteration.

    Rate this question:

  • 19. 

     

    • A.

      Disallow UDP 53 in from outside to DNS server

    • B.

      Allow UDP 53 in from DNS server to outside

    • C.

      Disallow TCP 53 in from secondaries or ISP server to DNS server

    • D.

      Block all UDP traffic

    Correct Answer
    A. Disallow UDP 53 in from outside to DNS server
    Explanation
    This answer suggests that the UDP port 53 should be blocked for incoming traffic from outside to the DNS server. This is because UDP port 53 is commonly used for DNS queries and allowing external access to this port could potentially expose the DNS server to unauthorized access or malicious attacks. By disallowing UDP 53 traffic from outside, the DNS server can be better protected.

    Rate this question:

  • 20. 

    When monitoring for both intrusion and security events between multiple computers, it is essential that the computers' clocks are synchronized. Synchronized time allows an administrator to reconstruct what took place during an attack against multiple computers. Without synchronized time, it is very difficult to determine exactly when specific events took place, and how events interlace. What is the name of the service used to synchronize time among multiple computers?

    • A.

      Universal Time Set (UTS)

    • B.

      Network Time Protocol (NTP)

    • C.

      SyncTime Service (STS)

    • D.

      Time-Sync Protocol (TSP)

    Correct Answer
    B. Network Time Protocol (NTP)
    Explanation
    The correct answer is Network Time Protocol (NTP). NTP is a service used to synchronize the clocks of multiple computers. By ensuring that all computers have synchronized time, an administrator can accurately reconstruct the sequence of events during an attack. Without synchronized time, it would be difficult to determine the exact timing and order of events. Universal Time Set (UTS), SyncTime Service (STS), and Time-Sync Protocol (TSP) are not valid terms or services related to time synchronization among multiple computers.

    Rate this question:

  • 21. 

    When investigating a potential e-mail crime, what is your first step in the investigation?

    • A.

      Trace the IP address to its origin

    • B.

      Write a report

    • C.

      Determine whether a crime was actually committed

    • D.

      Recover the evidence

    Correct Answer
    A. Trace the IP address to its origin
    Explanation
    The first step in investigating a potential e-mail crime is to trace the IP address to its origin. This is important because the IP address can provide crucial information about the location and identity of the sender. By tracing the IP address, investigators can gather evidence that can help in identifying and apprehending the perpetrator. It is a crucial step in the investigation process as it can lead to further steps such as obtaining search warrants or subpoenas to gather more evidence.

    Rate this question:

  • 22. 

    If a suspect computer is located in an area that may have toxic chemicals, you MUST:

    • A.

      Coordinate with the HAZMAT team

    • B.

      Determine a way to obtain the suspect computer

    • C.

      Assume the suspect machine is contaminated

    • D.

      Do not enter alone

    Correct Answer
    A. Coordinate with the HAZMAT team
    Explanation
    If a suspect computer is located in an area that may have toxic chemicals, it is important to coordinate with the HAZMAT team. This is necessary because the presence of toxic chemicals can pose a risk to the individuals involved in the investigation. The HAZMAT team is trained and equipped to handle hazardous materials safely, so their involvement ensures that proper precautions are taken. By coordinating with the HAZMAT team, the investigators can ensure their own safety and minimize the risk of contamination or harm.

    Rate this question:

  • 23. 

    The following excerpt is taken from a honeypot log. The log captures activities across three days. There are several intrusion attempts; however only a few are successful. (Note: The objective of this question is to test whether the student can read basic information from log entries and interpret the nature of the attack.)

    • A.

      An IDS evasion technique

    • B.

      A buffer overflow attempt

    • C.

      A DNS zone transfer

    • D.

      Data being retrieved from 63.226.81.13

    Correct Answer
    A. An IDS evasion technique
    Explanation
    The given answer is "An IDS evasion technique". This can be inferred from the fact that the log captures intrusion attempts and only a few are successful. An IDS evasion technique refers to methods used by attackers to avoid detection by an Intrusion Detection System (IDS). This suggests that the successful intrusion attempts were able to bypass the IDS, indicating the use of an IDS evasion technique.

    Rate this question:

  • 24. 

    What happens when a file is deleted by a Microsoft operating system using the FAT file system?

    • A.

      Only the reference to the file is removed from the FAT

    • B.

      The file is erased and cannot be recovered

    • C.

      A copy of the file is stored and the original file is erased

    • D.

      The file is erased but can be recovered

    Correct Answer
    A. Only the reference to the file is removed from the FAT
    Explanation
    When a file is deleted by a Microsoft operating system using the FAT file system, only the reference to the file is removed from the File Allocation Table (FAT). This means that the operating system no longer recognizes the file as being present, but the actual data of the file remains intact on the storage device. Although the file may appear to be erased, it can still be recovered using specialized software that can access the underlying data.

    Rate this question:

  • 25. 

    The following excerpt is taken from a honeypot log that was hosted at lab.wiretrip.net. Snort reported Unicode attacks from 213.116.251.162. The File Permission Canonicalization vulnerability (UNICODE attack) allows scripts to be run in arbitrary folders that do not normally have the right to run scripts. The attacker tries a Unicode attack and eventually succeeds in displaying boot.ini. He then switches to playing with Microsoft’s Remote Desktop Services (RDS), via msadcs.dll. The RDS vulnerability allows a malicious user to construct SQL statements that will execute shell commands (such as CMD.EXE) on the IIS server. He does a quick query to discover that the directory exists, and a query to msadcs.dll shows that it is functioning correctly. The attacker makes an RDS query which results in the commands run as shown below. What can you infer from the exploit given?

    • A.

      It is a local exploit where the attacker logs in using username johna2k

    • B.

      There are two attackers on the system - johna2k and haxedj00

    • C.

      The attack is a remote exploit and the hacker downloads three files

    • D.

      The attacker is unsuccessful in spawning a shell as he has specified a high end UDP port

    Correct Answer
    C. The attack is a remote exploit and the hacker downloads three files
    Explanation
    The given excerpt mentions that the attacker switches to playing with Microsoft's Remote Desktop Services (RDS) and constructs SQL statements that execute shell commands on the IIS server. It is mentioned that the attacker makes an RDS query which results in the commands run. This indicates that the attack is a remote exploit, as the attacker is able to execute commands on the server remotely. Additionally, it is mentioned that the attacker downloads three files, further confirming that the attack is remote and involves downloading files from the server.

    Rate this question:

  • 26. 

    What term is used to describe a cryptographic technique for embedding information into something else for the sole purpose of hiding that information from the casual observer?

    • A.

      Rootkit

    • B.

      Key escrow

    • C.

      Steganography

    • D.

      Offset

    Correct Answer
    C. Steganography
    Explanation
    Steganography is the correct answer because it refers to the practice of concealing information within another form of data, such as an image or audio file, in order to keep it hidden from anyone who is not the intended recipient. This technique is commonly used to ensure the secrecy and confidentiality of sensitive information, as it allows for the covert transmission of messages without arousing suspicion from the casual observer.

    Rate this question:

  • 27. 

    During the course of an investigation, you locate evidence that may prove the innocence of the suspect of the investigation. You must maintain an unbiased opinion and be objective in your entire fact finding process. Therefore, you report this evidence. This type of evidence is known as:

    • A.

      Inculpatory evidence

    • B.

      Mandatory evidence

    • C.

      Exculpatory evidence

    • D.

      Terrible evidence

    Correct Answer
    C. Exculpatory evidence
    Explanation
    Exculpatory evidence is evidence that tends to prove the innocence of the suspect or defendant in a criminal investigation or trial. It is important for investigators to maintain an unbiased and objective approach to the fact-finding process, which includes reporting any evidence that may support the innocence of the suspect. By doing so, investigators ensure a fair and just investigation, allowing for the possibility of exonerating the individual if the evidence is strong enough.

    Rate this question:

  • 28. 

    If you discover a criminal act while investigating a corporate policy abuse, it becomes a public sector investigation and should be referred to law enforcement?

    • A.

      True

    • B.

      False

    Correct Answer
    A. True
    Explanation
    If a criminal act is discovered during an investigation into corporate policy abuse, it should be referred to law enforcement because it becomes a public sector investigation. This means that the investigation is no longer solely focused on internal policy violations within the organization, but now involves potential criminal activity that falls under the jurisdiction of law enforcement agencies. Referring the case to law enforcement ensures that appropriate legal actions can be taken against the individuals involved in the criminal act.

    Rate this question:

  • 29. 

    What binary coding is used most often for eMail purposes?

    • A.

      Multi-purpose Internet Mail Extensions (MIME)

    • B.

      Unix-to-Unix ENCODE-ing (UUEncode)

    • C.

      Internet Message Access Protocol (IMAP)

    • D.

      Simple Mail Transfer Protocol (SMTP)

    Correct Answer
    A. Multi-purpose Internet Mail Extensions (MIME)
    Explanation
    MIME is the most commonly used binary coding for email purposes. MIME allows different types of data to be included in email messages, such as images, audio, and video files, by encoding them into a binary format. This encoding ensures that the data can be transmitted and received correctly across different email systems and platforms. It also allows email clients to interpret and display the data correctly, regardless of the file type. Therefore, MIME is widely used to handle the encoding and decoding of binary data in email communications.

    Rate this question:

  • 30. 

    If you see the files "zer0.tar.gz" and "copy.tar.gz" on a Linux system while doing an investigation, what can you conclude?

    • A.

      The system files have been copied by a remote attacker

    • B.

      The system administrator has created an incremental backup

    • C.

      The system has been compromised using a t0rnrootkit

    • D.

      Nothing in particular as these can be operational files

    Correct Answer
    D. Nothing in particular as these can be operational files
    Explanation
    Based on the given information, the presence of the files "zer0.tar.gz" and "copy.tar.gz" on a Linux system does not provide enough evidence to conclude anything specific. These files could potentially be operational files or have other legitimate purposes. Therefore, no particular conclusion can be drawn from their presence alone.

    Rate this question:

  • 31. 

    From the following spam mail header, identify the host IP that sent this spam?

    • A.

      137.189.96.52

    • B.

      8.12.1.0

    • C.

      203.218.39.20

    • D.

      203.218.39.50

    Correct Answer
    C. 203.218.39.20
    Explanation
    The correct answer is 203.218.39.20. This is the host IP that sent the spam, as indicated by the question.

    Rate this question:

  • 32. 

    Diskcopy is:

    • A.

      A utility by AccessData

    • B.

      A standard MS-DOS command

    • C.

      Digital Intelligence utility

    • D.

      Dd copying tool

    Correct Answer
    B. A standard MS-DOS command
    Explanation
    Diskcopy is a standard MS-DOS command. MS-DOS is an operating system developed by Microsoft for IBM-compatible personal computers. The diskcopy command is used to create an identical copy of a floppy disk or a hard drive. It is a built-in utility in MS-DOS and allows users to duplicate disks for backup or distribution purposes.

    Rate this question:

  • 33. 

    Sectors in hard disks typically contain how many bytes?

    • A.

      256

    • B.

      512

    • C.

      1024

    • D.

      2048

    Correct Answer
    B. 512
    Explanation
    Sectors in hard disks typically contain 512 bytes. This is the standard sector size used in most hard drives. A sector is the smallest unit of data that can be read from or written to a hard disk. It is important to have a consistent sector size across different hard drives to ensure compatibility and efficient data storage and retrieval.

    Rate this question:

  • 34. 

    Area density refers to:

    • A.

      The amount of data per disk

    • B.

      The amount of data per partition

    • C.

      The amount of data per square inch

    • D.

      The amount of data per platter

    Correct Answer
    A. The amount of data per disk
    Explanation
    Area density refers to the amount of data stored on a given disk. It measures the quantity of data that can be packed into a specific area of the disk's surface. This metric is typically expressed as the amount of data per square inch. The higher the area density, the more information can be stored on the disk, resulting in greater storage capacity. It is an important factor in determining the efficiency and effectiveness of data storage systems.

    Rate this question:

  • 35. 

    Corporate investigations are typically easier than public investigations because:

    • A.

      The users have standard corporate equipment and software

    • B.

      The investigator does not have to get a warrant

    • C.

      The investigator has to get a warrant

    • D.

      The users can load whatever they want on their machines

    Correct Answer
    B. The investigator does not have to get a warrant
    Explanation
    In corporate investigations, the investigator does not have to get a warrant. Unlike public investigations, where law enforcement agencies typically need a warrant to search and seize evidence, corporate investigations are conducted within the boundaries of the company's policies and regulations. This means that the investigator can access and examine corporate equipment and software without the need for a warrant. However, it is important to note that this does not imply unlimited access, as investigators still need to adhere to legal and ethical guidelines while conducting their investigations.

    Rate this question:

  • 36. 

    Which of the following should a computer forensics lab, used for investigations, have?

    • A.

      Isolation

    • B.

      Restricted access

    • C.

      Open access

    • D.

      An entry log

    Correct Answer
    B. Restricted access
    Explanation
    A computer forensics lab used for investigations should have restricted access. This is necessary to ensure the security and integrity of the evidence being analyzed. Restricted access means that only authorized personnel should be allowed to enter the lab, reducing the risk of tampering or unauthorized access to the equipment and data. By implementing restricted access protocols, the lab can maintain a controlled environment where the chain of custody can be properly maintained, and the integrity of the evidence can be preserved.

    Rate this question:

  • 37. 

    Jason is the security administrator of ACMA metal Corporation. One day he notices the company's Oracle database server has been compromised and the customer information along with financial data has been stolen. The financial loss will be in millions of dollars if the database gets into the hands of the competitors. Jason wants to report this crime to the law enforcement agencies immediately. Which organization coordinates computer crimes investigations throughout the United States?

    • A.

      Internet Fraud Complaint Center

    • B.

      Local or national office of the U.S. Secret Service

    • C.

      National Infrastructure Protection Center

    • D.

      CERT Coordination Center

    Correct Answer
    B. Local or national office of the U.S. Secret Service
    Explanation
    The correct answer is the local or national office of the U.S. Secret Service. The U.S. Secret Service is responsible for investigating and preventing crimes related to financial fraud, including computer crimes. They have the jurisdiction and expertise to handle cases involving the theft of customer information and financial data. Reporting the crime to the U.S. Secret Service would ensure that the appropriate law enforcement agency is notified and can take action to investigate and apprehend the perpetrators.

    Rate this question:

  • 38. 

    Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?

    • A.

      Network-based Intrusion Detection System (NIDS)

    • B.

      Host-based Intrusion Detection System (HIDS)

    • C.

      Anomaly detection

    • D.

      Signature recognition

    Correct Answer
    B. Host-based Intrusion Detection System (HIDS)
    Explanation
    Host-based Intrusion Detection Systems (HIDS) are installed on individual host systems and monitor activities and events occurring on those systems. Since HIDS focus on the behavior and activities of individual hosts, they are more likely to produce false alarms due to the unpredictable behaviors of users and networks. Users may engage in unusual activities or network behaviors may change, leading to false alarms being triggered by the HIDS. In contrast, Network-based Intrusion Detection Systems (NIDS) monitor network traffic and are less affected by the specific behaviors of individual hosts, making them less prone to false alarms in this context. Anomaly detection and signature recognition are techniques used by both NIDS and HIDS to identify potential intrusions.

    Rate this question:

  • 39. 

    You should make at least ___ bit-stream copies of a suspect drive?

    • A.

      1

    • B.

      2

    • C.

      3

    • D.

      4

    Correct Answer
    B. 2
    Explanation
    When conducting forensic analysis on a suspect drive, it is recommended to make at least two bit-stream copies. This is important because it ensures the preservation of the original evidence and allows for multiple copies to be used for different purposes. Having multiple copies also reduces the risk of data loss or corruption during the analysis process. Additionally, it enables multiple investigators or experts to work on different copies simultaneously, increasing efficiency and collaboration.

    Rate this question:

  • 40. 

    Why should you note all cable connections for a computer you want to seize as evidence?

    • A.

      To know what outside connections existed

    • B.

      In case other devices were connected

    • C.

      To know what peripheral devices exist

    • D.

      To know what hardware existed

    Correct Answer
    A. To know what outside connections existed
    Explanation
    By noting all cable connections for a computer that is being seized as evidence, one can determine what outside connections existed. This information is crucial as it can provide insights into potential sources of data transfer or communication with external devices. It allows investigators to understand the extent of the computer's network connections and identify any potential threats or additional devices that might have been connected to it.

    Rate this question:

  • 41. 

    What header field in the TCP/IP protocol stack involves the hacker exploit known as the Ping of Death?

    • A.

      ICMP header field

    • B.

      TCP header field

    • C.

      IP header field

    • D.

      UDP header field

    Correct Answer
    B. TCP header field
    Explanation
    The correct answer is TCP header field. The Ping of Death is a hacker exploit that involves sending an oversized ICMP Echo Request packet to a target system. This causes the target system to crash or become unresponsive. The TCP header field is responsible for managing and controlling the transmission of data between devices over a network. In the case of the Ping of Death, the hacker manipulates the TCP header field to send a malicious packet that overwhelms the target system, leading to a denial of service.

    Rate this question:

  • 42. 

    What method of computer forensics will allow you to trace all ever-established user accounts on a Windows 2000 sever the course of its lifetime?

    • A.

      Forensic duplication of hard drive

    • B.

      Analysis of volatile data

    • C.

      Comparison of MD5 checksums

    • D.

      Review of SIDs in the Registry

    Correct Answer
    C. Comparison of MD5 checksums
    Explanation
    The comparison of MD5 checksums is not the correct method for tracing user accounts on a Windows 2000 server. MD5 checksums are used to verify the integrity of data, not to trace user accounts. This method involves generating a unique hash value for a file or data and comparing it with the original hash value to check for any changes or tampering. It is not relevant to tracing user accounts on a server.

    Rate this question:

  • 43. 

    Which response organization tracks hoaxes as well as viruses?

    • A.

      National Photographic Interpretation Center (NIPC)

    • B.

      Federal Computer Incident Response Center (FedCIRC)

    • C.

      Computer Emergency Response Team (CERT)

    • D.

      Computer Incident Advisory  Capability (CIAC)

    • E.

      Joint Cybersecurity Coordination Center (JC3) 

    • F.

      Department Of Energy - Computer Incident Response Center (DOE-CIRC)

    Correct Answer
    D. Computer Incident Advisory  Capability (CIAC)
    Explanation
    The correct answer is Computer Incident Advisory Capability (CIAC). CIAC is an organization that not only tracks viruses but also hoaxes. They provide information and guidance to organizations and individuals to help prevent and respond to computer security incidents.

    Rate this question:

  • 44. 

    Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?

    • A.

      18 U.S.C. § 1029 - Fraud and related activity in connection with access devices

    • B.

      18 U.S.C. § 1362 - Communication lines, stations or systems

    • C.

      18 U.S.C. § 2511 - Interception and disclosure of wire, oral, or electronic communications prohibited

    • D.

      18 U.S.C. § 2703 - Required disclosure of customer communications or records

    Correct Answer
    A. 18 U.S.C. § 1029 - Fraud and related activity in connection with access devices
    Explanation
    The correct answer is 18 U.S.C. § 1029 - Fraud and related activity in connection with access devices. This law specifically deals with fraud and related activities involving access devices such as routers. It addresses the illegal use of access devices, including unauthorized access, trafficking, and possession of stolen access devices. This law aims to protect against fraudulent activities and unauthorized access to computer systems using access devices.

    Rate this question:

  • 45. 

    Documents created by Office programs such as Word, Excel, and PowerPoint contain a code, based off of the Media Access Control (MAC) address, or unique identifier, of the machine upon which the document was written. What is this code called?

    • A.

      The Microsoft Virtual Machine Identifier

    • B.

      The Personal Application Protocol

    • C.

      The Globally Unique IDentifier (GUID)

    • D.

      The Individual ASCII String

    Correct Answer
    C. The Globally Unique IDentifier (GUID)
    Explanation
    The code mentioned in the question is called the Globally Unique IDentifier (GUID). It is a unique identifier assigned to a document created by Office programs. This identifier is based on the Media Access Control (MAC) address of the machine on which the document was written.

    Rate this question:

  • 46. 

    What TCP/UDP port does the toolkit program netstat use?

    • A.

      TCP/UDP Port 7

    • B.

      TCP/UDP Port 15

    • C.

      TCP/UDP Port 23

    • D.

      TCP/UDP Port 69

    Correct Answer
    B. TCP/UDP Port 15
    Explanation
    The correct answer is TCP/UDP Port 15. Netstat is a command-line tool used to display active network connections, listening ports, and other network statistics. It can be used to monitor network traffic and troubleshoot network-related issues. In this case, netstat uses TCP/UDP Port 15 to display the active network connections and associated information.

    Rate this question:

  • 47. 

    When investigating a network that uses Dynamic Host Configuration Protocol (DHCP) to assign Internet Protocol (IP) addresses, where would you look to determine which system, identified by it’s Media Access Control (MAC) address, had a specific IP address at a specific time?

    • A.

      On the individual computer's ARP cache

    • B.

      In the Web Server log files

    • C.

      In the DHCP Server log files

    • D.

      There is no way to determine the specific IP address

    Correct Answer
    C. In the DHCP Server log files
    Explanation
    In a network that uses DHCP to assign IP addresses, the DHCP server is responsible for assigning and managing IP addresses. The DHCP server maintains a log file that records the IP address assignments made to each system. By looking into the DHCP server log files, one can determine which system, identified by its MAC address, had a specific IP address at a specific time. This log file provides a record of the IP address assignments made by the DHCP server, allowing for the identification of the system associated with a particular IP address.

    Rate this question:

  • 48. 

    Bob has been trying to penetrate a remote production system for the past two weeks. This time however, he is able to get into the system. He was able to use the System for a period of three weeks. However, law enforcement agencies were recording his every activity and this was later presented as evidence. The organization had used a Virtual Environment to trap Bob. What is a Virtual Environment?

    • A.

      A Honeypot that traps hackers

    • B.

      A system Using Trojaned commands

    • C.

      An environment set up after the user logs in

    • D.

      An environment set up before a user logs in

    Correct Answer
    A. A Honeypot that traps hackers
    Explanation
    A Virtual Environment in this context refers to a Honeypot that traps hackers. It is a simulated environment that is designed to attract and deceive potential attackers, like Bob, into thinking they have gained unauthorized access to a system. In reality, the actions performed within the Virtual Environment are monitored and recorded by law enforcement agencies, allowing them to gather evidence against the hacker. This technique is commonly used to gather intelligence on hacking activities and to protect real production systems from unauthorized access.

    Rate this question:

  • 49. 

    To make sure the evidence you recover and analyze with computer forensics software can be admitted in court, you must test and validate the software. What group is actively providing tools and creating procedures for testing and validating computer forensics software?

    • A.

      Computer Forensics Tools and Validation Committee (CFTVC)

    • B.

      Association of Computer Forensics Software Manufactures (ACFSM)

    • C.

      National Institute of Standards and Technology (NIST)

    • D.

      Society for Valid Forensics Tools and Testing (SVFTT)

    Correct Answer
    C. National Institute of Standards and Technology (NIST)
    Explanation
    The National Institute of Standards and Technology (NIST) is actively providing tools and creating procedures for testing and validating computer forensics software. This organization is known for its expertise in developing standards and guidelines for various fields, including computer forensics. By testing and validating the software, NIST ensures that it meets the necessary requirements and can be considered reliable and accurate in a court of law.

    Rate this question:

  • 50. 

    With regard to using an anti-virus scanner during a computer forensics investigation, you should:

    • A.

      Scan the suspect hard drive before beginning an investigation

    • B.

      Never run a scan on your forensics workstation because it could change your systems configuration

    • C.

      Scan your forensics workstation at intervals of no more than once every five minutes during an investigation

    • D.

      Scan your forensics workstation before beginning an investigation

    Correct Answer
    D. Scan your forensics workstation before beginning an investigation
    Explanation
    It is important to scan the forensics workstation before beginning an investigation to ensure that there are no existing malware or viruses present that could potentially compromise the investigation. By scanning the workstation beforehand, any potential threats can be identified and removed, ensuring the integrity of the investigation process.

    Rate this question:

Quiz Review Timeline +

Our quizzes are rigorously reviewed, monitored and continuously updated by our expert board to maintain accuracy, relevance, and timeliness.

  • Current Version
  • Mar 22, 2023
    Quiz Edited by
    ProProfs Editorial Team
  • Apr 18, 2019
    Quiz Created by
    Dale
Back to Top Back to top
Advertisement
×

Wait!
Here's an interesting quiz for you.

We have other quizzes matching your interest.