accurate answers
A forensic image is:
A. A picture taken of the physical components of a compromised system
B. The documentation surrounding a piece of evidence
C. A zipped container of all forensic evidence regarding a specific
incident
D. An identical copy of a piece of digital evidence Ans✓✓✓D. An
identical copy of a piece of digital evidence
An on-site forensics team is always more cost effective for organizations
than hiring an off-site team.
A. True
B. False Ans✓✓✓B. False
,Hash values can be calculated for any file or data set, including full hard
drives.
A. True
B. False Ans✓✓✓A. True
Installing patches, disabling services, removing accounts, and re-
imaging systems are example methods of:
A. Collection
B. Containment
C. Detection
D. Eradication
E. All of the above
, F. None of the above Ans✓✓✓D. Eradication
Locard's Principle speculates that:
A. Every piece of evidence must pass the verifiability, repeatability, and
traceability test
B. Every system connected to another must be identifiable
C. Every 'contact' between two people or systems will leave a trace
D. Every 'contact' between two people or systems will be logged
Ans✓✓✓C. Every 'contact' between two people or systems will leave a
trace
Once an intruder has identified targets to attack and the vulnerabilities to
exploit, they will begin their attack. Which phase of the attacker
methodology does this fall under?
A. Breach