Q: 11
An organization decided to strengthen the security of its network by studying and analyzing the
behavior of attackers. For this purpose, Steven, a security analyst, was instructed to deploy a device
to bait attackers. Steven selected a solution that appears to contain very useful information to lure
attackers and find their locations and techniques.
Identify the type of device deployed by Steven in the above scenario.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Below is the syntax of a command-line utility that displays active TCP connections and ports on which
the computer is listening.
netstat [-a] [-e] [-n] [-o] [-p Protocol] [-r] [-s] [Interval]
Identify the netstat parameter that displays active TCP connections and includes the process ID (PID)
for each connection.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Sam, a digital forensic expert, is working on a case related to file tampering in a system at the
administrative department of an organization. In this process, Sam started performing the following
steps to analyze the acquired data to draw conclusions related to the case.
1.Analyze the file content for data usage.
2.Analyze the date and time of file creation and modification.
3.Find the users associated with file creation, access, and file modification.
4.Determine the physical storage location of the file.
5.Generate a timeline.
6.Identify the root cause of the incident.
Identify the type of analysis performed by Sam in the above scenario.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Wesley, a professional hacker, deleted a confidential file in a compromised system using the
“/bin/rm/” command to deny access to forensic specialists.
Identify the operating system on which Don has performed the file carving act.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Which of the following hives in the Windows Registry hierarchical database is volatile in nature and
contains file-extension association information and programmatic identifier (ProgID), Class ID
(CLSID), and Interface ID (IID) data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2