Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

ICT 378 QUESTION AND ANSWERS-VERIFIED BY EXPERTS

Rating
-
Sold
-
Pages
35
Grade
A+
Uploaded on
16-06-2021
Written in
2020/2021

Topic 1 A chain-of-evidence form, which is used to document what has and has not been done with the original evidence and forensic copies of the evidence, is also known as a _______. a. single-evidence form b. multi-evidence form c. evidence custody form d. evidence tracking form _______ describes an accusation of fact that a crime has been committed. a. Attrition b. Attribution c. Allegation d. Assignment If a police officer or investigator has sufficient cause to support a search warrant, the prosecuting attorney might direct him or her to submit a _______. a. exhibit b. verdict c. affidavit d. memo _______ is not one of the functions of the investigations triad. a. Digital investigations b. Data recovery c. Vulnerability/threat assessment and risk management d. Network intrusion detection and incident response _______ is not recommended for a digital forensics workstation. a. A text editor tool b. A write-blocker device c. An SCSI card d. Remote access software _______ must be included in an affidavit to support an allegation in order to justify a warrant. a. Verdicts b. Witness c. Exhibits d. Subpoenas The _______ is not one of the three stages of a typical criminal case. a. complaint b. investigationc. civil suit d. prosecution The sale of sensitive or confidential company information to a competitor is known as _______. a. industrial espionage b. industrial sabotage c. industrial collusion d. industrial betrayal The term _______ describes a database containing informational records about crimes that have been committed previously by a criminal. a. police ledger b. police blotter c. police blogger d. police recorder Which Microsoft OS below is the least intrusive to disks in terms of changing data? a. Windows 95 b. Windows XP c. Windows 7 d. MS-DOS 6.22 Which option below is not a standard systems analysis step? a. Determine a preliminary design or approach to the case b. Obtain and copy an evidence drive c. Share evidence with experts outside of the investigation d. Mitigate or minimize the risks Within a computing investigation, the ability to perform a series of steps again and again to produce the same results is known as _______. a. repeatable findings b. reloadable steps c. verifiable reporting d. evidence reporting According to the National Institute of Standards and Technology (NIST), digital forensics involves scientifically examining and analyzing data from computer storage media so that it can be used as evidence in court. True / False All suspected industrial espionage cases should be treated as civil case investigations. True / FalseIf you turn evidence over to law enforcement and begin working under their direction, you have become an agent of law enforcement, and are subject to the same restrictions on search and seizure as a law enforcement agent. True / False Most digital investigations in the private sector involve misuse of computing assets. True / False User groups for a specific type of system can be very useful in a forensics investigation. True / FalseTopic 2 An investigator wants to capture all data on a SATA drive connected to a Linux system. What should the investigator use for the "if=" portion of the dcfldd command? a. /dev/hda b. /dev/hda1 c. /dev/sda d. /dev/sda1 _______ can be used with the dcfldd command to compare an image file to the original medium. a. compare b. cmp c. vf d. imgcheck

Show more Read less
Institution
Course

Content preview

Topic 1

A chain-of-evidence form, which is used to document what has and has not been done
with the original evidence and forensic copies of the evidence, is also known as a
_______.
a. single-evidence form
b. multi-evidence form
c. evidence custody form
d. evidence tracking form

_______ describes an accusation of fact that a crime has been committed.
a. Attrition
b. Attribution
c. Allegation
d. Assignment

If a police officer or investigator has sufficient cause to support a search warrant, the
prosecuting attorney might direct him or her to submit a _______.
a. exhibit
b. verdict
c. affidavit
d. memo

_______ is not one of the functions of the investigations triad.
a. Digital investigations
b. Data recovery
c. Vulnerability/threat assessment and risk management
d. Network intrusion detection and incident response



_______ is not recommended for a digital forensics workstation.
a. A text editor tool
b. A write-blocker device
c. An SCSI card
d. Remote access software

_______ must be included in an affidavit to support an allegation in order to justify a
warrant.
a. Verdicts
b. Witness
c. Exhibits
d. Subpoenas

The _______ is not one of the three stages of a typical criminal case.
a. complaint
b. investigation

,c. civil suit
d. prosecution

The sale of sensitive or confidential company information to a competitor is known as
_______.
a. industrial espionage
b. industrial sabotage
c. industrial collusion
d. industrial betrayal

The term _______ describes a database containing informational records about crimes
that have been committed previously by a criminal.
a. police ledger
b. police blotter
c. police blogger
d. police recorder

Which Microsoft OS below is the least intrusive to disks in terms of changing data?
a. Windows 95
b. Windows XP
c. Windows 7
d. MS-DOS 6.22

Which option below is not a standard systems analysis step?
a. Determine a preliminary design or approach to the case
b. Obtain and copy an evidence drive
c. Share evidence with experts outside of the investigation
d. Mitigate or minimize the risks

Within a computing investigation, the ability to perform a series of steps again and
again to produce the same results is known as _______.
a. repeatable findings
b. reloadable steps
c. verifiable reporting
d. evidence reporting

According to the National Institute of Standards and Technology (NIST), digital forensics
involves scientifically examining and analyzing data from computer storage media so
that it can be used as evidence in court.
True / False

All suspected industrial espionage cases should be treated as civil case investigations.
True / False

,If you turn evidence over to law enforcement and begin working under their direction,
you have become an agent of law enforcement, and are subject to the same restrictions
on search and seizure as a law enforcement agent.
True / False

Most digital investigations in the private sector involve misuse of computing assets.
True / False

User groups for a specific type of system can be very useful in a forensics investigation.
True / False

, Topic 2

An investigator wants to capture all data on a SATA drive connected to a Linux system.
What should the investigator use for the "if=" portion of the dcfldd command?
a. /dev/hda
b. /dev/hda1
c. /dev/sda
d. /dev/sda1

_______ can be used with the dcfldd command to compare an image file to the original
medium.
a. compare
b. cmp
c. vf
d. imgcheck

The _______ copies evidence of intrusions to an investigation workstation automatically
for further analysis over the network.
a. intrusion detection system
b. active defense mechanism
c. total awareness system
d. intrusion monitoring system

The Linux command _______ can be used to list the current disk devices connected to the
computer.
a. ls -l
b. fdisk -l
c. show drives
d. geom

The Linux command _____ can be used to write bit-stream data to files.
a. write
b. dd
c. cat
d. dump

The _______ switch can be used with the split command to adjust the size of segmented
volumes created by the dd command.

Written for

Institution
Course

Document information

Uploaded on
June 16, 2021
Number of pages
35
Written in
2020/2021
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$13.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Examhack Stanford University
Follow You need to be logged in order to follow users or courses
Sold
303
Member since
5 year
Number of followers
238
Documents
999
Last sold
5 days ago
EASY A GRADE!!

Here, you will find simple, articulate well-researched education material for you. .... ALL WORK HAS PASSED WITHOUT NEEDING REVISIONS AND BY THE RUBRIC.

3.8

62 reviews

5
32
4
11
3
5
2
4
1
10

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions