

Information Security
Final Exam
Course Introduction
Information Security is a course that explores the principles, techniques, and practices involved in protecting digital information and systems from unauthorized access, misuse, or destruction. Students will learn about key concepts such as confidentiality, integrity, and availability, while examining security threats, vulnerabilities, and risk management strategies. Topics include cryptography, authentication, access control, network security, security policies, and ethical and legal issues in information security. Through practical examples and case studies, students will develop the skills to assess security needs, implement protective measures, and respond to security incidents in various computing environments.
Recommended Textbook Guide to Computer Forensics and Investigations 4th Edition by Bill Nelson
Available Study Resources on Quizplus
16 Chapters
768 Verified Questions
768 Flashcards
Source URL: https://quizplus.com/study-set/1690

Page 2

Chapter 1: Computer Forensics and Investigations As a Profession
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33478
Sample Questions
Q1) In general, a criminal case follows three stages: the complaint, the investigation, and the ____.
A) litigation
B) allegation
C) blotter
D) prosecution
Answer: D
Q2) specifies who has the legal right to initiate an investigation, who can take possession of evidence, and who can have access to evidence
A)Computer forensics
B)Network forensics
C)Litigation
D)Xtree Gold
E)Case law
F)HTCIA
G)Affidavit
H)Industrial espionage
I)Line of authority
Answer: I
To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Understanding Computer Investigations
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33479
Sample Questions
Q1) In any computing investigation, you should be able to repeat the steps you took and produce the same results. This capability is referred to as ____.
A) checked values
B) verification
C) evidence backup
D) repeatable findings
Answer: D
Q2) extracts all related e-mail address information for Web-based e-mail investigations
A)FTK's Internet Keyword Search
B)Data recovery
C)Free space
D)Interrogation
E)Forensic workstation
F)Norton DiskEdit
G)MS-DOS 6.22
H)Multi-evidence form
I)Self-evaluation
Answer: A
To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: The Investigators Office and Laboratory
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33480
Sample Questions
Q1) In the ____, you justify acquiring newer and better resources to investigate computer forensics cases.
A) risk evaluation
B) business case
C) configuration plan
D) upgrade policy
Answer: B
Q2) By using ____ to attract new customers or clients, you can justify future budgets for the lab's operation and staff.
A) pricing
B) marketing
C) budgeting
D) changing Answer: B
Q3) Lab costs can be broken down into daily, ____, and annual expenses.
A) weekly
B) monthly
C) bimonthly
D) quarterly
Answer: D
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Data Acquisition
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33481
Sample Questions
Q1) What are the advantages and disadvantages of using raw data acquisition format?
Q2) The ____ command creates a raw format file that most computer forensics analysis tools can read, which makes it useful for data acquisitions.
A) fdisk
B) dd
C) man
D) raw
Q3) shows the known drives connected to your computer
A)SafeBack
B)WinZip
C)Data acquisition
D)AFF
E)IXimager
F)fdisk -l
G)Lossy compression
H)Jaz disk
I)EnCase
Q4) What are some of the design goals of AFF?
Q5) There are two types of acquisitions: static acquisitions and ____________________ acquisitions.
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Processing Crime and Incident Scenes
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33482
Sample Questions
Q1) Some computer cases involve dangerous settings. For these types of investigations, you must rely on the skills of _________________________ teams to recover evidence from the scene.
Q2) Briefly describe the process of obtaining a search warrant.
Q3) covert surveillance product
A)Innocent information
B)AFIS
C)EnCase Enterprise Edition
D)FOIA
E)IOCE
F)Low-level investigations
G)Hearsay
H)Spector
I)HAZMAT
Q4) Most federal courts have interpreted computer records as ____ evidence.
A) conclusive
B) regular
C) hearsay
D) direct
Q5) How can you determine who is in charge of an investigation?
Page 7
To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Working With Windows and Dos Systems
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33483
Sample Questions
Q1) The purpose of the ____ is to provide a mechanism for recovering encrypted files under EFS if there's a problem with the user's original private key.
A) certificate escrow
B) recovery certificate
C) administrator certificate
D) root certificate
Q2) A ____ allows you to create a representation of another computer on an existing physical computer.
A) virtual file
B) logic drive
C) logic machine
D) virtual machine
Q3) ____ is a batch file containing customized settings for MS-DOS that runs automatically.
A) Autoexec.bat
B) Config.sys
C) Io.sys
D) Command.com
Q4) What are BitLocker's current hardware and software requirements?
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Current Computer Forensics Tools
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33484
Sample Questions
Q1) What are the five major function categories of any computer forensics tool?
Q2) Illustrate how to consider hardware needs when planning your lab budget.
Q3) To make a disk acquisition with En.exe requires only a PC running ____ with a 12-volt power connector and an IDE, a SATA, or a SCSI connector cable.
A) UNIX
B) MAC OS X
C) Linux
D) MS-DOS
Q4) Hardware manufacturers have designed most computer components to last about ____________________ months between failures.
Q5) A forensics workstation consisting of a laptop computer with a built-in LCD monitor and almost as many bays and peripherals as a stationary workstation is also known as a
A) stationary workstation
B) field workstation
C) lightweight workstation
D) portable workstation
Q6) The ____________________ function is the most demanding of all tasks for computer investigators to master.
Page 9
To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Macintosh and Linux Boot Processes and File Systems
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33485
Sample Questions
Q1) The final component in the UNIX and Linux file system is a(n) ____, which is where directories and files are stored on a disk drive.
A) superblock
B) data block
C) boot block
D) inode block
Q2) ISO standard for CDs
A)File Manager
B)Inode blocks
C)ISO 9660
D)LILO
E)Clumps
F)Volume
G)ls
H)Catalog
I)Finder
Q3) GPL and BSD variations are examples of open-source software.
A)True
B)False
Q4) What are the functions of the superblock on a UNIX or Linux file system?
To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Computer Forensics Analysis and Validation
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33486
Sample Questions
Q1) A nonsteganographic graphics file has a different size than an identical steganographic graphics file.
A)True
B)False
Q2) FTK provides two options for searching for keywords: indexed search and ____________________ search.
Q3) ____________________ search catalogs all words on the evidence disk so that FTK can find them quickly.
Q4) How can you validate the integrity of raw format image files with ProDiscover?
Q5) a password recovery program available from AccessData
A)Court orders for discovery
B)Investigation plan
C)Digital Intelligence PDWipe
D)Live search
E)Cabinet
F)PRTK
G)Validating digital evidence
H)MD5
I)System Commander
Q6) What are the file systems supported by FTK for forensic analysis?
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Recovering Graphics Files
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33487
Sample Questions
Q1) Present a list of categories covered under copyright laws in the U.S.
Q2) tool used to rebuild image file headers
A)Pixels
B)Hex Workshop
C)Adobe Illustrator
D)Microsoft Office Picture Manager
E)JPEG
F)Steganalysis tools
G)GIMP
H)XIF
I)Metafile graphics
Q3) Give a brief overview of copyright laws pertaining to graphics within and outside the U.S.
Q4) ____ steganography places data from the secret file into the host file without displaying the secret data when you view the host file in its associated program.
A) Replacement
B) Append
C) Substitution
D) Insertion
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Virtual Machines, Network Forensics, and Live Acquisitions
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33488
Sample Questions
Q1) The PSTools ____ kills processes by name or process ID.
A) PsExec
B) PsList
C) PsKill
D) PsShutdown
Q2) helps manage snort rules so that you can specify what items to ignore as regular traffic and what items should raise alarms
A)Cyberforensics
B)Ethereal
C)Tripwire
D)PsGetSid
E)PsLoggedOn
F)Trojan horse
G)Knoppix
H)PsShutdown
I)oinkmaster
Q3) PsList from PsTools allows you to list detailed information about processes.
A)True
B)False
Q4) When are live acquisitions useful?
To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: E-Mail Investigations
Available Study Resources on Quizplus for this Chatper
48 Verified Questions
48 Flashcards
Source URL: https://quizplus.com/quiz/33489
Sample Questions
Q1) GroupWise has ____ ways of organizing the mailboxes on the server.
A) 2
B) 3
C) 4
D) 5
Q2) What kind of information can you find in an e-mail header?
Q3) Describe how e-mail account names are created on an intranet environment.
Q4) Administrators usually set e-mail servers to ____________________ logging mode.
Q5) An e-mail address in the Return-Path line of an e-mail header is usually indicated as the ____________________ field in an e-mail message.
Q6) E-mail messages are distributed from one central server to many connected client computers, a configuration called ____.
A) client/server architecture
B) central distribution architecture
C) client architecture
D) peer-to-peer architecture
Q7) Vendor-unique e-mail file systems, such as Microsoft .pst or .ost, typically use ____________________ formatting, which can be difficult to read with a text or hexadecimal editor.
To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Cell Phone and Mobile Device Forensics
Available Study Resources on Quizplus for this Chatper
37 Verified Questions
37 Flashcards
Source URL: https://quizplus.com/quiz/33490
Sample Questions
Q1) The file system for a SIM card is a ____ structure.
A) volatile
B) circular
C) hierarchical
D) linear
Q2) The 3G standard was developed by the ______________________ under the United Nations.
Q3) Mobile devices can range from simple phones to small computers, also called ______________________.
Q4) ____ cards are found most commonly in GSM devices and consist of a microprocessor and from 16 KB to 4 MB of EEPROM.
A) SD
B) MMC
C) SDD
D) SIM
Q5) Most Code Division Multiple Access (CDMA) networks conform to IS-95, created by the ______________________.
Q6) What are the four categories of information that can be retrieved from a SIM card?
To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: Report Writing for High-Tech Investigations
Available Study Resources on Quizplus for this Chatper
48 Verified Questions
48 Flashcards
Source URL: https://quizplus.com/quiz/33491
Sample Questions
Q1) computer forensics software tool
A)Decimal numbering
B)Lay witness
C)FTK
D)Examination plan
E)Signposts
F)Verbal report
G)Spoliation
H)Conclusion section
I)MD5
Q2) Attorneys can now submit documents electronically in many courts; the standard format in federal courts is ____.
A) Microsoft Word (DOC)
B) Portable Document Format (PDF)
C) Encapsulated Postscript (EPS)
D) Postscript (PS)
Q3) A verbal report is more structured than a written report.
A)True
B)False
Q4) What are the areas of investigation usually addressed by a verbal report?
To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: Expert Testimony in High-Tech Investigations
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/33492
Sample Questions
Q1) Discuss any potential problems with your attorney ____ a deposition.
A) before
B) after
C) during
D) during direct examination at
Q2) The ____ is the most important part of testimony at a trial.
A) cross-examination
B) direct examination
C) rebuttal
D) motions in limine
Q3) If a microphone is present during your testimony, place it ____ to eight inches from you.
A) 3
B) 4
C) 5
D) 6
Q4) Like a job resume, your CV should be geared for a specific trial.
A)True
B)False
Q5) What are the procedures followed during a trial?
Page 17
To view all questions and flashcards with answers, click on the resource link above.

Chapter 16: Ethics for the Expert Witness
Available Study Resources on Quizplus for this Chatper
35 Verified Questions
35 Flashcards
Source URL: https://quizplus.com/quiz/33493
Sample Questions
Q1) provides a well-defined, simple guide for expected behavior of computer forensics examiners
A)Ethics
B)Federal Rules of Evidence (FRE)
C)Disqualification
D)IACIS
Q2) ____ questions can give you the factual structure to support and defend your opinion.
A) Setup
B) Compound
C) Rapid-fire
D) Hypothetical
Q3) The American Bar Association (ABA) is a licensing body.
A)True
B)False
Q4) help you maintain your self-respect and the respect of your profession
A)Ethics
B)Federal Rules of Evidence (FRE)
C)Disqualification
D)IACIS
To view all questions and flashcards with answers, click on the resource link above. Page 18