Investigations 2023 Questions and Answers with complete
solution
What are passive footprints?
Data unintentionally left behind during typical internet activities
If an investigator in New York state wants to document 2:15 PM on May 31, 2017,
how would that moment in time be notated according the ISO 8601 directive?
(New York is in the Eastern Time Zone which is -5 UTC, and observes daylight
savings)
2017-05-31T18:15:00Z
What is considered a common best practice for an analysis environment in terms
of Internet connectivity?
Only be connected to the internet when it is absolutely necessary
Which of the following is the order of email packet encapsulation?
A. IP Header, Ethernet Header, TCP Header, Email MessageB. Email Message,
Ethernet Header, IP Header, TCP HeaderC. Email Message, TCP Header, IP Header,
Ethernet HeaderD. Ethernet Header, Email Header, TCP Header, IP Header; Not A
Which of the following best describes a domain name?
An identifier used for network and application addressing purposes
What website can be used to look up detailed archive data about a domain name?
domaintools.com
Information that a web browser reveals about a system or user during typical
internet browsing activities is known as:
Browser leak
An investigator will get better results if s/he uses their own Facebook account to
'friend' the individual they're investigating.
False
When a data packet is being created and prepared for transport, whether the
target computer?s IP address is on the same network or on a remote network, is
not a consideration.
False
Which of the following is an indicator that encryption is in use on a system?
None of the above
Peer-to-Peer networks aren't popular because they're expensive and difficult to
deploy.
False
What is a common tactic used by organizations to defend against domain name
typo-squatting?
Domain Parking
Remote access software must be used between two identical device types.
False
Encrypted or zipped files by their very nature, contain unknown or untrusted files.
True
Which of the following is NOT a piece in the encryption process?