What is the First Step required in preparing a computer for forensics investigation?
Show answer and explanation
Correct answer: A
312-49V8 Online Exam
180 questions available ยท Page 1 of 18
What is the First Step required in preparing a computer for forensics investigation?
Correct answer: A
Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.
Correct answer: A
Which of the following commands shows you the names of all open shared files on a server and number of file locks on each file?
Correct answer: B
The Recycle Bin exists as a metaphor for throwing files away, but it also allows user to retrieve and restore files. Once the file is moved to the recycle bin, a record is added to the log file that exists in the Recycle
Bin.
Which of the following files contains records that correspond to each deleted file in the Recycle Bin?
Correct answer: A
Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive.
Which of the following statements is correct while dealing with local archives?
Correct answer: A
Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
Correct answer: A
Which of the following commands shows you all of the network services running on Windows-based servers?
Correct answer: A
Email archiving is a systematic approach to save and protect the data contained in emails so that it can tie easily accessed at a later date.
Correct answer: A
Which of the following commands shows you the NetBIOS name table each?
Correct answer: A
Windows Security Accounts Manager (SAM) is a registry file which stores passwords in a hashed format.
SAM file in Windows is located at:
Correct answer: A
FAT32 is a 32-bit version of FAT file system using smaller clusters and results in efficient storage capacity.
What is the maximum drive size supported?
Correct answer: B
In which step of the computer forensics investigation methodology would you run MD5 checksum on the evidence?
Correct answer: D
Network forensics allows Investigators to inspect network traffic and logs to identify and locate the attack system
Network forensics can reveal: (Select three answers)
Correct answers: A, B, C
Determine the message length from following hex viewer record:

Correct answer: D
TCP/IP (Transmission Control Protocol/Internet Protocol) is a communication protocol used to connect different hosts in the Internet. It contains four layers, namely the network interface layer. Internet layer, transport layer, and application layer.
Which of the following protocols works under the transport layer of TCP/IP?
Correct answer: A
Which of the following statements does not support the case assessment?
Correct answer: C
Wireless access control attacks aim to penetrate a network by evading WLAN access control measures, such as AP MAC filters and Wi-Fi port access controls.
Which of the following wireless access control attacks allows the attacker to set up a rogue access point outside the corporate perimeter, and then lure the employees of the organization to connect to it?
Correct answer: D
File deletion is a way of removing a file from a computer's file system.
What happens when a file is deleted in windows7?
Correct answer: B
What is cold boot (hard boot)?
Correct answer: A
When a file or folder is deleted, the complete path, including the original file name, is stored in a special hidden file called "INF02" in the Recycled folder. If the INF02 file is deleted, it is re-created when you___________.
Correct answer: A