Asset correct answers Any resource, product, process, system, or digital or physical entity
that has value to an organization and must be protected.
Acoustical systems correct answers Detection systems that use strategically placed
microphones to detect any sound made during a forced entry.
Best evidence rule correct answers A rule which states that when evidence, such as a
document or recording, is presented, only the original will be accepted unless a legitimate
reason exists for not using the original.
Blacklisting correct answers Configuring unacceptable email addresses, Internet addresses,
websites, applications, or some other identifiers as bad senders or as denied.
Bollards correct answers Short vertical posts placed at entrances to buildings and lining
sidewalks that help provide protection from vehicles that might either intentionally or
unintentionally crash into or enter the building or injure pedestrians.
Chain of custody correct answers A list that shows who controlled evidence, who secured the
evidence, and who obtained the evidence.
Circumstantial evidence correct answers Evidence that provides inference of information
from other intermediate relevant facts.
Civil investigation correct answers An investigation that occurs when one organization or
party suspects another organization of civil wrongdoing.
Class 1 gate correct answers A gate suitable for residential use.
Class 2 gate correct answers A gate suitable for commercial usage.
Class 3 gate correct answers A gate suitable for industrial usage.
Class 4 gate correct answers A gate that is used for a restricted area.
Clipping levels correct answers Set a baseline for normal user errors, and violations
exceeding that threshold will be recorded for analysis of why the violations occurred.
Closed-circuit television (CCTV) system correct answers A system that uses sets of cameras
that can either be monitored in real time or record days of activity that can be viewed as
needed at a later time.
Cold site correct answers A leased facility that contains only electrical and communications
wiring, air conditioning, plumbing, and raised flooring.
Conclusive evidence correct answers Evidence that requires no other corroboration.
, Content analysis correct answers Analysis of the contents of a drive or software. Drive
content analysis gives a report detailing the types of data by percentage. Software content
analysis determines the purpose of the software.
Copy backup correct answers A backup that backs up all the files, much like to a full backup,
but does not reset the file's archive bit.
Corroborative evidence correct answers Evidence that supports another piece of evidence.
Crime scene correct answers The environment in which potential evidence exists.
Criminal investigation correct answers An investigation that is carried out because a federal,
state, or local law has been violated.
Daily backup correct answers A backup in which a file's timestamp is used to determine
whether it needs to be archived.
Data clearing correct answers An attack that renders information unrecoverable using a
keyboard. This type of attack extracts information from data storage media by executing
software utilities, keystrokes, or other system resources from a keyboard.
Data loss prevention (DLP) software correct answers Software that attempts to prevent data
leakage.
Data purging correct answers A process renders information unrecoverable against laboratory
attacks (forensics). It can be done using a method such as degaussing to make the old data
unavailable even with forensics.
Differential backup correct answers A backup in which all files that have been changed since
the last full backup are backed up and the archive bit for each file is not cleared.
Direct evidence correct answers Evidence that proves or disproves a fact through oral
testimony, based on information gathered through the witness's senses.
Disk imaging correct answers The process of creating an exact image of the contents of a
hard drive.
Dual control correct answers A security measure that requires two employees to be available
to complete a specific task. This security measure is part of separation of duties.
Duress correct answers A situation that occurs when an employee is coerced to commit an
action by another party. This is a particular concern for high-level management and
employees with high security clearances because they have access to extra assets.
Egress monitoring correct answers Monitoring that occurs when an organization monitors the
outbound flow of information from one network to another.
Electronic discovery (eDiscovery) correct answers Litigation or government investigations
that deal with the exchange of information in electronic format as part of the discovery
process.