
Course Introduction
![]()

Course Introduction
Computer Forensics introduces students to the principles and practices of investigating digital crimes and incidents. The course covers the identification, preservation, analysis, and presentation of digital evidence from computers, networks, and mobile devices. Students will learn about forensic tools, methodologies for legal evidence handling, file recovery, and techniques to uncover hidden or deleted data. Emphasis is placed on legal and ethical considerations, as well as real-world case studies that illustrate the application of computer forensics in law enforcement, corporate environments, and cybersecurity investigations.
Recommended Textbook
Principles of Incident Response and Disaster Recovery 1st Edition by Michael E. Whitman
Available Study Resources on Quizplus
11 Chapters
549 Verified Questions
549 Flashcards
Source URL: https://quizplus.com/study-set/2243

Page 2

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44623
Sample Questions
Q1) A specific and identifiable instance of a general threat.
A)Threat agent
B)Intellectual property
C)Hacker
D)Computer viruses
E)Trojan
F)Risk management
G)Likelihood
H)Residual risk
I)Standards
Answer: A
Q2) What is difference between access control lists and configuration rules?
Answer: Access control lists (ACLs): Lists,matrices,and capability tables governing the rights and privileges of a particular user to a particular system.
Configuration rules: The specific configuration codes entered into security systems to guide the execution of the system when information is passing through it.
To view all questions and flashcards with answers, click on the resource link above.
Page 3

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44624
Sample Questions
Q1) The blackmail of an organization for information assets is an example of a(n)____.
A)deliberate act of sabotage
B)act of human error
C)deliberate act of trespass
D)deliberate act of information distortion
Answer: D
Q2) List five deliberate software attacks.
Answer: 1.E-mail viruses and worms
2.E-mail-based social engineering
3.Web-based malicious scripts
4.Denial-of-service attacks on servers
5.Spyware and malicious adware
Q3) _________________________ are often used as the basis for the development of recovery strategies and as a determinant as to whether or not to implement the recovery strategies during a disaster situation.
Answer: Recovery time objectives
Recovery time objectives (RTOs) RTOs
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44625
Q1) The term ____ is used to describe the circumstances that cause the IR team to be activated and the IR plan to be initiated.
A)problem
B)after-action
C)trigger
D)war gaming
Answer: C
Q2) Resource multipliers.
A)Distributed incident response teams
B)Teamwork skills
C)Education and awareness
D)IR plan
E)After-action review
F)Full-interruption testing
G)Catalyst
H)Blackhole
I)Semtex
Answer: C
To view all questions and flashcards with answers, click on the resource link above. Page 5

Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/44626
Sample Questions
Q1) List five reasons why you would acquire and use an IDS.
Q2) What are the advantages and disadvantages of HIDS?
Q3) A(n)____ is a type of attack on information assets in which the instigator attempts to gain unauthorized entry into a system or network or disrupt the normal operations of a system or network.
A)intrusion
B)alert
C)event
D)honeypot
Q4) A ____ is a type of IDS that is similar to the NIDS,reviews the log files generated by servers,network devices,and even other IDSs.
A)honeypot
B)alarm cluster
C)log file monitor
D)DNS cache
Q5) The purpose of a NIDS is to look for patterns within network traffic that indicate an intrusion event is underway or about to begin.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 6

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44627
Sample Questions
Q1) Rehearsals that closely match reality are called ____.
A)virtual reality
B)computer games
C)forensics
D)war games
Q2) Discuss five key steps in the Apprehend and Prosecute reaction strategy.
Q3) A(n)____ is a document containing contact information for the individuals that need to be notified in the event of an actual incident.
A)sequential roster
B)hierarchical roster
C)alert roster
D)root roster
Q4) The immediate determination of the scope of the breach of confidentiality,integrity,and availability of information and information assets is called
Q5) What are the key steps in the Protect and Forget reaction strategy?
Q6) Once an incident has been contained,and system control has been regained,incident ____________________ can begin.
Q7) What is the three-step methodology followed by computer forensics?
To view all questions and flashcards with answers, click on the resource link above. Page 7

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44628
Sample Questions
Q1) What are the disadvantages of a time-share?
Q2) Provides only rudimentary services and facilities.
A)RAID level 2
B)Remote journaling
C)NAS
D)Cold site
E)Mutual agreement
F)Service agreement
G)BC plan
H)Incremental backup
I)Differential backup
Q3) ____ is the transfer of live transactions to an off-site facility.
A)Electronic vaulting
B)Remote journaling
C)Database shadowing
D)Data warehousing
Q4) The disadvantage of a full backup is that it takes a comprehensive snapshot of the organization's system.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 8

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44629
Sample Questions
Q1) What is involved in training for the DR plan?
Q2) The ________________________________________ assembles a disaster recovery team.
Q3) In disaster recovery,most triggers are in response to one or more natural events.
A)True
B)False
Q4) ____ are those that occur suddenly,with little warning,taking the lives of people and destroying the means of production.
A)Slow onset disasters
B)Communication disasters
C)Rapid onset disasters
D)Data disasters
Q5) Web site ____ solutions should ensure the reliability and availability of the Web site and its resources.
A)security
B)contingency
C)maintenance
D)cache
Q6) List six strategies that should be considered for desktop computer and portable systems. Page 9
To view all questions and flashcards with answers, click on the resource link above.
Page 10

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44630
Sample Questions
Q1) What is the purpose of the disaster management team?
Q2) Network recovery teams may be used to replacing downed systems,but it is unlikely that they have experience in physically repairing damaged systems.
A)True
B)False
Q3) Requires that a contact person call each and every person on the roster.
A)Storage recovery team
B)Vendor relationships
C)Testing
D)Alert roster
E)Sequential roster
F)Recovery phase
G)Resumption phase
H)Restoration phase
I)Data-management practices
Q4) Perhaps the last formal activity the organization performs before declaring the disaster officially over is the ____________________.
Q5) What is the difference between the business interface team and the logistics team?
To view all questions and flashcards with answers, click on the resource link above. Page 11
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44631
Sample Questions
Q1) BC is specifically designed to get the organization's most critical services up and running as quickly as possible in order to enable the continued operation of the organization and thereby assure its existence and minimize the financial losses from the disruption.
A)True
B)False
Q2) A ____ is a service agency that provides a service for a fee.
A)time-share
B)service bureau
C)mobile site
D)mirrored site
Q3) What is the seven-step process used to develop and maintain a viable contingency planning program?
Q4) Unlike DR planning,the identification of critical business functions and the resources to support them are the cornerstone of the process used to create the business continuity (BC)plan.
A)True
B)False

Page 12
Q5) How does remote journaling differ from electronic vaulting?
Q6) Why should the should BC and DR teams contain different individuals?
To view all questions and flashcards with answers, click on the resource link above. Page 13

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44632
Sample Questions
Q1) One in which the organization does not have confidence will not survive a real continuity operation.
A)Trigger point
B)Preparation undertaken by an organization
C)Network recovery team
D)Security
E)Insurance
F)BC plan
G)BC review
H)Information systems security control
I)Plan
Q2) The ____ team works to works to establish short- and longterm networks,including the network hardware (hubs,switches,and routers)and wiring,and Internet and Intranet connectivity.
A)business continuity management team
B)operations team
C)computer setup team
D)network recovery team
Q3) What are the requirements for the CBCP certification?
Q4) What is the purpose of the BC review?
To view all questions and flashcards with answers, click on the resource link above. Page 14

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/44633
Sample Questions
Q1) In the medical profession,the first hour after injury is referred to as the
Q2) ____ is the group charged with analyzing vulnerabilities,evaluating existing plans,and developing and implementing the comprehensive crisis management program.
A)Crisis management planning committee
B)Humanitarian planning committee
C)Emergency response committee
D)Cross-training planning committee
Q3) ____________________ is the process that enables an organization to cope with any loss of personnel with a minimum degree of disruption to the functionality of the organization.
Q4) When a crisis occurs,having the right resources available at the right place can mean the difference between success and catastrophe.List six of these critical resources.
Q5) List four typical causes of a crisis.
Q6) EAPs fill the need to talk through issues that people are unable to deal with on their own.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 15