Skip to main content

Information Security Final Exam - 768 Verified Questions

Page 1


Information Security

Final Exam

Course Introduction

Information Security is a course that explores the principles, techniques, and practices involved in protecting digital information and systems from unauthorized access, misuse, or destruction. Students will learn about key concepts such as confidentiality, integrity, and availability, while examining security threats, vulnerabilities, and risk management strategies. Topics include cryptography, authentication, access control, network security, security policies, and ethical and legal issues in information security. Through practical examples and case studies, students will develop the skills to assess security needs, implement protective measures, and respond to security incidents in various computing environments.

Recommended Textbook Guide to Computer Forensics and Investigations 4th Edition by Bill Nelson

Available Study Resources on Quizplus

16 Chapters

768 Verified Questions

768 Flashcards

Source URL: https://quizplus.com/study-set/1690

Page 2

Chapter 1: Computer Forensics and Investigations As a Profession

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33478

Sample Questions

Q1) In general, a criminal case follows three stages: the complaint, the investigation, and the ____.

A) litigation

B) allegation

C) blotter

D) prosecution

Answer: D

Q2) specifies who has the legal right to initiate an investigation, who can take possession of evidence, and who can have access to evidence

A)Computer forensics

B)Network forensics

C)Litigation

D)Xtree Gold

E)Case law

F)HTCIA

G)Affidavit

H)Industrial espionage

I)Line of authority

Answer: I

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Understanding Computer Investigations

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33479

Sample Questions

Q1) In any computing investigation, you should be able to repeat the steps you took and produce the same results. This capability is referred to as ____.

A) checked values

B) verification

C) evidence backup

D) repeatable findings

Answer: D

Q2) extracts all related e-mail address information for Web-based e-mail investigations

A)FTK's Internet Keyword Search

B)Data recovery

C)Free space

D)Interrogation

E)Forensic workstation

F)Norton DiskEdit

G)MS-DOS 6.22

H)Multi-evidence form

I)Self-evaluation

Answer: A

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: The Investigators Office and Laboratory

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33480

Sample Questions

Q1) In the ____, you justify acquiring newer and better resources to investigate computer forensics cases.

A) risk evaluation

B) business case

C) configuration plan

D) upgrade policy

Answer: B

Q2) By using ____ to attract new customers or clients, you can justify future budgets for the lab's operation and staff.

A) pricing

B) marketing

C) budgeting

D) changing Answer: B

Q3) Lab costs can be broken down into daily, ____, and annual expenses.

A) weekly

B) monthly

C) bimonthly

D) quarterly

Answer: D

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Data Acquisition

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33481

Sample Questions

Q1) What are the advantages and disadvantages of using raw data acquisition format?

Q2) The ____ command creates a raw format file that most computer forensics analysis tools can read, which makes it useful for data acquisitions.

A) fdisk

B) dd

C) man

D) raw

Q3) shows the known drives connected to your computer

A)SafeBack

B)WinZip

C)Data acquisition

D)AFF

E)IXimager

F)fdisk -l

G)Lossy compression

H)Jaz disk

I)EnCase

Q4) What are some of the design goals of AFF?

Q5) There are two types of acquisitions: static acquisitions and ____________________ acquisitions.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Processing Crime and Incident Scenes

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33482

Sample Questions

Q1) Some computer cases involve dangerous settings. For these types of investigations, you must rely on the skills of _________________________ teams to recover evidence from the scene.

Q2) Briefly describe the process of obtaining a search warrant.

Q3) covert surveillance product

A)Innocent information

B)AFIS

C)EnCase Enterprise Edition

D)FOIA

E)IOCE

F)Low-level investigations

G)Hearsay

H)Spector

I)HAZMAT

Q4) Most federal courts have interpreted computer records as ____ evidence.

A) conclusive

B) regular

C) hearsay

D) direct

Q5) How can you determine who is in charge of an investigation?

Page 7

To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Working With Windows and Dos Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33483

Sample Questions

Q1) The purpose of the ____ is to provide a mechanism for recovering encrypted files under EFS if there's a problem with the user's original private key.

A) certificate escrow

B) recovery certificate

C) administrator certificate

D) root certificate

Q2) A ____ allows you to create a representation of another computer on an existing physical computer.

A) virtual file

B) logic drive

C) logic machine

D) virtual machine

Q3) ____ is a batch file containing customized settings for MS-DOS that runs automatically.

A) Autoexec.bat

B) Config.sys

C) Io.sys

D) Command.com

Q4) What are BitLocker's current hardware and software requirements?

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Current Computer Forensics Tools

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33484

Sample Questions

Q1) What are the five major function categories of any computer forensics tool?

Q2) Illustrate how to consider hardware needs when planning your lab budget.

Q3) To make a disk acquisition with En.exe requires only a PC running ____ with a 12-volt power connector and an IDE, a SATA, or a SCSI connector cable.

A) UNIX

B) MAC OS X

C) Linux

D) MS-DOS

Q4) Hardware manufacturers have designed most computer components to last about ____________________ months between failures.

Q5) A forensics workstation consisting of a laptop computer with a built-in LCD monitor and almost as many bays and peripherals as a stationary workstation is also known as a

A) stationary workstation

B) field workstation

C) lightweight workstation

D) portable workstation

Q6) The ____________________ function is the most demanding of all tasks for computer investigators to master.

Page 9

To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Macintosh and Linux Boot Processes and File Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33485

Sample Questions

Q1) The final component in the UNIX and Linux file system is a(n) ____, which is where directories and files are stored on a disk drive.

A) superblock

B) data block

C) boot block

D) inode block

Q2) ISO standard for CDs

A)File Manager

B)Inode blocks

C)ISO 9660

D)LILO

E)Clumps

F)Volume

G)ls

H)Catalog

I)Finder

Q3) GPL and BSD variations are examples of open-source software.

A)True

B)False

Q4) What are the functions of the superblock on a UNIX or Linux file system?

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Computer Forensics Analysis and Validation

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33486

Sample Questions

Q1) A nonsteganographic graphics file has a different size than an identical steganographic graphics file.

A)True

B)False

Q2) FTK provides two options for searching for keywords: indexed search and ____________________ search.

Q3) ____________________ search catalogs all words on the evidence disk so that FTK can find them quickly.

Q4) How can you validate the integrity of raw format image files with ProDiscover?

Q5) a password recovery program available from AccessData

A)Court orders for discovery

B)Investigation plan

C)Digital Intelligence PDWipe

D)Live search

E)Cabinet

F)PRTK

G)Validating digital evidence

H)MD5

I)System Commander

Q6) What are the file systems supported by FTK for forensic analysis?

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Recovering Graphics Files

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33487

Sample Questions

Q1) Present a list of categories covered under copyright laws in the U.S.

Q2) tool used to rebuild image file headers

A)Pixels

B)Hex Workshop

C)Adobe Illustrator

D)Microsoft Office Picture Manager

E)JPEG

F)Steganalysis tools

G)GIMP

H)XIF

I)Metafile graphics

Q3) Give a brief overview of copyright laws pertaining to graphics within and outside the U.S.

Q4) ____ steganography places data from the secret file into the host file without displaying the secret data when you view the host file in its associated program.

A) Replacement

B) Append

C) Substitution

D) Insertion

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Virtual Machines, Network Forensics, and Live Acquisitions

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33488

Sample Questions

Q1) The PSTools ____ kills processes by name or process ID.

A) PsExec

B) PsList

C) PsKill

D) PsShutdown

Q2) helps manage snort rules so that you can specify what items to ignore as regular traffic and what items should raise alarms

A)Cyberforensics

B)Ethereal

C)Tripwire

D)PsGetSid

E)PsLoggedOn

F)Trojan horse

G)Knoppix

H)PsShutdown

I)oinkmaster

Q3) PsList from PsTools allows you to list detailed information about processes.

A)True

B)False

Q4) When are live acquisitions useful?

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: E-Mail Investigations

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/33489

Sample Questions

Q1) GroupWise has ____ ways of organizing the mailboxes on the server.

A) 2

B) 3

C) 4

D) 5

Q2) What kind of information can you find in an e-mail header?

Q3) Describe how e-mail account names are created on an intranet environment.

Q4) Administrators usually set e-mail servers to ____________________ logging mode.

Q5) An e-mail address in the Return-Path line of an e-mail header is usually indicated as the ____________________ field in an e-mail message.

Q6) E-mail messages are distributed from one central server to many connected client computers, a configuration called ____.

A) client/server architecture

B) central distribution architecture

C) client architecture

D) peer-to-peer architecture

Q7) Vendor-unique e-mail file systems, such as Microsoft .pst or .ost, typically use ____________________ formatting, which can be difficult to read with a text or hexadecimal editor.

To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Cell Phone and Mobile Device Forensics

Available Study Resources on Quizplus for this Chatper

37 Verified Questions

37 Flashcards

Source URL: https://quizplus.com/quiz/33490

Sample Questions

Q1) The file system for a SIM card is a ____ structure.

A) volatile

B) circular

C) hierarchical

D) linear

Q2) The 3G standard was developed by the ______________________ under the United Nations.

Q3) Mobile devices can range from simple phones to small computers, also called ______________________.

Q4) ____ cards are found most commonly in GSM devices and consist of a microprocessor and from 16 KB to 4 MB of EEPROM.

A) SD

B) MMC

C) SDD

D) SIM

Q5) Most Code Division Multiple Access (CDMA) networks conform to IS-95, created by the ______________________.

Q6) What are the four categories of information that can be retrieved from a SIM card?

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: Report Writing for High-Tech Investigations

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/33491

Sample Questions

Q1) computer forensics software tool

A)Decimal numbering

B)Lay witness

C)FTK

D)Examination plan

E)Signposts

F)Verbal report

G)Spoliation

H)Conclusion section

I)MD5

Q2) Attorneys can now submit documents electronically in many courts; the standard format in federal courts is ____.

A) Microsoft Word (DOC)

B) Portable Document Format (PDF)

C) Encapsulated Postscript (EPS)

D) Postscript (PS)

Q3) A verbal report is more structured than a written report.

A)True

B)False

Q4) What are the areas of investigation usually addressed by a verbal report?

To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: Expert Testimony in High-Tech Investigations

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33492

Sample Questions

Q1) Discuss any potential problems with your attorney ____ a deposition.

A) before

B) after

C) during

D) during direct examination at

Q2) The ____ is the most important part of testimony at a trial.

A) cross-examination

B) direct examination

C) rebuttal

D) motions in limine

Q3) If a microphone is present during your testimony, place it ____ to eight inches from you.

A) 3

B) 4

C) 5

D) 6

Q4) Like a job resume, your CV should be geared for a specific trial.

A)True

B)False

Q5) What are the procedures followed during a trial?

Page 17

To view all questions and flashcards with answers, click on the resource link above.

Chapter 16: Ethics for the Expert Witness

Available Study Resources on Quizplus for this Chatper

35 Verified Questions

35 Flashcards

Source URL: https://quizplus.com/quiz/33493

Sample Questions

Q1) provides a well-defined, simple guide for expected behavior of computer forensics examiners

A)Ethics

B)Federal Rules of Evidence (FRE)

C)Disqualification

D)IACIS

Q2) ____ questions can give you the factual structure to support and defend your opinion.

A) Setup

B) Compound

C) Rapid-fire

D) Hypothetical

Q3) The American Bar Association (ABA) is a licensing body.

A)True

B)False

Q4) help you maintain your self-respect and the respect of your profession

A)Ethics

B)Federal Rules of Evidence (FRE)

C)Disqualification

D)IACIS

To view all questions and flashcards with answers, click on the resource link above. Page 18

Turn static files into dynamic content formats.

Create a flipbook
Information Security Final Exam - 768 Verified Questions by Quizplus - Issuu