Skip to main content

Cybersecurity Fundamentals Exam Preparation Guide - 768 Verified Questions

Page 1


Cybersecurity Fundamentals Exam Preparation

Guide

Course Introduction

Cybersecurity Fundamentals introduces students to the core principles and practices essential for protecting computer systems, networks, and data from digital threats. The course covers foundational topics such as types of cyberattacks, cryptography, security protocols, risk management, ethical considerations, and the legal landscape of cybersecurity. Through a combination of theoretical knowledge and practical exercises, students develop an understanding of how to detect vulnerabilities, implement defensive strategies, and respond to security incidents, preparing them for further study or entry-level roles in the cybersecurity field.

Recommended Textbook Guide to Computer Forensics and Investigations 4th Edition by Bill Nelson

Available Study Resources on Quizplus

16 Chapters

768 Verified Questions

768 Flashcards

Source URL: https://quizplus.com/study-set/1690 Page 2

Chapter 1: Computer Forensics and Investigations As a Profession

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33478

Sample Questions

Q1) Without a warning banner, employees might have an assumed ____ when using a company's computer systems and network accesses.

A) line of authority

B) right of privacy

C) line of privacy

D) line of right

Answer: B

Q2) The ____ group manages investigations and conducts forensic analysis of systems suspected of containing evidence related to an incident or a crime.

A) network intrusion detection

B) computer investigations

C) incident response

D) litigation

Answer: B

Q3) By the 1970s, electronic crimes were increasing, especially in the financial sector.

A)True

B)False

Answer: True

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Understanding Computer Investigations

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33479

Sample Questions

Q1) To conduct your investigation and analysis, you must have a specially configured personal computer (PC) known as a ____.

A) mobile workstation

B) forensic workstation

C) forensic lab

D) recovery workstation

Answer: B

Q2) an essential part of professional growth

A)FTK's Internet Keyword Search

B)Data recovery

C)Free space

D)Interrogation

E)Forensic workstation

F)Norton DiskEdit

G)MS-DOS 6.22

H)Multi-evidence form

I)Self-evaluation

Answer: I

Q3) A(n) ____________________ lists each piece of evidence on a separate page. Answer: single-evidence form

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: The Investigators Office and Laboratory

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33480

Sample Questions

Q1) Defense contractors during the Cold War were required to shield sensitive computing systems and prevent electronic eavesdropping of any computer emissions. The U.S. Department of Defense calls this special computer-emission shielding ____.

A) TEMPEST

B) RAID

C) NISPOM

D) EMR

Answer: A

Q2) certification program that regulates how crime labs are organized and managed

A)FireWire

B)Guidance Software

C)Business case

D)F.R.E.D.C.i.Disaster recovery plan

E)ASCLD/LAB

F)SIG

G)MAN

H)Norton Ghost

Answer: E

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Data Acquisition

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33481

Sample Questions

Q1) What are the requirements for acquiring data on a suspect computer using Linux?

Q2) process of copying data

A)SafeBack

B)WinZip

C)Data acquisition

D)AFF

E)IXimager

F)fdisk -l

G)Lossy compression

H)Jaz disk

I)EnCase

Q3) The ____ command creates a raw format file that most computer forensics analysis tools can read, which makes it useful for data acquisitions.

A) fdisk

B) dd

C) man

D) raw

Q4) Explain the sparse data copy method for acquiring digital evidence.

Q5) There are two types of acquisitions: static acquisitions and ____________________ acquisitions.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Processing Crime and Incident Scenes

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33482

Sample Questions

Q1) Evidence is commonly lost or corrupted through ____, which involves police officers and other professionals who aren't part of the crime scene processing team.

A) onlookers

B) HAZMAT teams

C) FOIA laws

D) professional curiosity

Q2) ISPs can investigate computer abuse committed by their customers.

A)True

B)False

Q3) Real-time surveillance requires ____ data transmissions between a suspect's computer and a network server.

A) poisoning

B) sniffing

C) blocking

D) preventing

Q4) Corporate investigators always have the authority to seize all computers equipments during a corporate investigation.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Working With Windows and Dos Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33483

Sample Questions

Q1) When Microsoft created Windows 95, it consolidated initialization (.ini) files into the

A) IniRecord

B) Inidata

C) Registry

D) Metadata

Q2) Records in the MFT are referred to as ____.

A) hyperdata

B) metadata

C) inodes

D) infodata

Q3) One way to examine a partition's physical level is to use a disk editor, such as Norton

DiskEdit, WinHex, or Hex Workshop.

A)True

B)False

Q4) A ____ is a column of tracks on two or more disk platters.

A) cylinder

B) sector

C) track

D) head

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Current Computer Forensics Tools

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33484

Sample Questions

Q1) Many password recovery tools have a feature that allows generating potential lists for a ____ attack.

A) brute-force

B) password dictionary

C) birthday

D) salting

Q2) software-enabled write-blocker

A)JFIF

B)Lightweight workstation

C)Pagefile.sys

D)Salvaging

E)Raw data

F)PDBlock

G)Norton DiskEdit

H)Stationary workstation

I)SafeBack

Q3) Explain the advantages and disadvantages of GUI forensics tools.

Q4) Explain the validation of evidence data process.

Q5) What are some of the advantages of using command-line forensics tools?

Q6) Explain the difference between repeatable results and reproducible results.

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Macintosh and Linux Boot Processes and File Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33485

Sample Questions

Q1) Mac OS utility that handles reading, writing, and storing data to physical media

A)File Manager

B)Inode blocks

C)ISO 9660

D)LILO

E)Clumps

F)Volume

G)ls

H)Catalog

I)Finder

Q2) The standard Linux file system is ____.

A) NTFS

B) Ext3fs

C) HFS+

D) Ext2fs

Q3) There are ____ tracks available for the program area on a CD.

A) 45

B) 50

C) 99

D) 100

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Computer Forensics Analysis and Validation

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33486

Sample Questions

Q1) one of the most critical aspects of computer forensics

A)Court orders for discovery

B)Investigation plan

C)Digital Intelligence PDWipe

D)Live search

E)Cabinet

F)PRTK

G)Validating digital evidence

H)MD5

I)System Commander

Q2) Briefly describe how to use steganography for creating digital watermarks.

Q3) Marking bad clusters data-hiding technique is more common with ____ file systems.

A) NTFS

B) FAT

C) HFS

D) Ext2fs

Q4) FTK provides two options for searching for keywords: indexed search and ____________________ search.

Q5) How does the Known File Filter program work?

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Recovering Graphics Files

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33487

Sample Questions

Q1) When working with image files, computer investigators also need to be aware of ____ laws to guard against copyright violations.

A) international

B) forensics

C) copyright

D) civil

Q2) Explain how someone can use a disk editor tool to mark clusters as "bad" clusters.

Q3) Give a brief overview of copyright laws pertaining to graphics within and outside the U.S.

Q4) image format derived from the TIFF file format

A)Pixels

B)Hex Workshop

C)Adobe Illustrator

D)Microsoft Office Picture Manager

E)JPEG

F)Steganalysis tools

G)GIMP

H)XIF

I)Metafile graphics

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Virtual Machines, Network Forensics, and Live Acquisitions

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33488

Sample Questions

Q1) ____ is a good tool for extracting information from large Libpcap files.

A) Nmap

B) Tcpslice

C) Pcap

D) TCPcap

Q2) The U.K. Honeynet Project has created the ____________________. It contains the honeywall and honeypot on a bootable memory stick.

Q3) Most packet sniffers operate on layer 2 or ____ of the OSI model.

A) 1

B) 3

C) 5

D) 7

Q4) A ____ is a computer set up to look like any other machine on your network, but it lures the attacker to it.

A) honeywall

B) honeypot

C) honeynet

D) honeyhost

Page 13

Q5) The PSTools ____________________ tool allows you to suspend processes.

Q6) Explain The Auditor tool.

To view all questions and flashcards with answers, click on the resource link above.

Page 14

Chapter 12: E-Mail Investigations

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/33489

Sample Questions

Q1) Like UNIX e-mail servers, Exchange maintains logs to track e-mail communication.

A)True

B)False

Q2) In UNIX e-mail servers, the ____________________ file simply specifies where to save different types of e-mail log files.

Q3) All e-mail servers are databases that store multiple users' e-mails.

A)True

B)False

Q4) An e-mail address in the Return-Path line of an e-mail header is usually indicated as the ____________________ field in an e-mail message.

Q5) ____ contains configuration information for Sendmail, allowing the investigator to determine where the log files reside.

A) /etc/sendmail.cf

B) /etc/syslog.conf

C) /etc/var/log/maillog

D) /var/log/maillog

Q6) Vendor-unique e-mail file systems, such as Microsoft .pst or .ost, typically use ____________________ formatting, which can be difficult to read with a text or hexadecimal editor.

Page 15

To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Cell Phone and Mobile Device Forensics

Available Study Resources on Quizplus for this Chatper

37 Verified Questions

37 Flashcards

Source URL: https://quizplus.com/quiz/33490

Sample Questions

Q1) How can you isolate a mobile device from incoming signals?

Q2) TDMA refers to the ____ standard, which introduced sleep mode to enhance battery life.

A) IS-136

B) IS-195

C) IS-236

D) IS-361

Q3) What are some of the features offered by SIMCon?

Q4) What is some of the information that can be stored in a cell phone?

Q5) What are the four categories of information that can be retrieved from a SIM card?

Q6) The 3G standard was developed by the ______________________ under the United Nations.

Q7) ____ cards are found most commonly in GSM devices and consist of a microprocessor and from 16 KB to 4 MB of EEPROM.

A) SD

B) MMC

C) SDD

D) SIM

Page 16

Q8) What is the general procedure to access the content on a mobile phone SIM card?

To view all questions and flashcards with answers, click on the resource link above.

Chapter 14: Report Writing for High-Tech Investigations

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/33491

Sample Questions

Q1) Reports and logs generated by forensic tools are typically in plaintext format, a word processor format, or ____ format.

A) PDF

B) HTML

C) PS

D) TXT

Q2) In the past, the method for expressing an opinion has been to frame a ____ question based on available factual evidence.

A) hypothetical

B) nested

C) challenging

D) contradictory

Q3) The report's ____ should restate the objectives, aims, and key questions and summarize your findings with clear, concise statements.

A) abstract

B) conclusion

C) introduction

D) reference

Q4) What do you need to consider to produce clear, concise reports?

To view all questions and flashcards with answers, click on the resource link above. Page 17

Chapter 15: Expert Testimony in High-Tech Investigations

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/33492

Sample Questions

Q1) How can you deal with rapid-fire questions during a cross-examination?

Q2) part of the discovery process for trial

A)Plaintiff

B)Motion in limine

C)Voir dire of venireman

D)Opening statements

E)Discovery deposition

F)CV

G)Testimony preservation deposition

H)Voir dire

I)MD5

Q3) At a trial, _____________________ are statements that organize the evidence and state the applicable law.

Q4) Explain the differences between discovery deposition and testimony preservation deposition.

Q5) ____ is a written list of objections to certain testimony or exhibits.

A) Defendant

B) Empanelling the jury

C) Plaintiff

D) Motion in limine

To view all questions and flashcards with answers, click on the resource link above. Page 18

Chapter 16: Ethics for the Expert Witness

Available Study Resources on Quizplus for this Chatper

35 Verified Questions

35 Flashcards

Source URL: https://quizplus.com/quiz/33493

Sample Questions

Q1) help you maintain your self-respect and the respect of your profession

A)Ethics

B)Federal Rules of Evidence (FRE)

C)Disqualification

D)IACIS

Q2) What are some of the requirements included in the HTCIA core values?

Q3) For psychologists, the most broadly accepted set of guidelines governing their conduct as experts is the _____________________ (APA's) Ethical Principles of Psychologists and Code of Conduct.

Q4) The ____ Ethics Code cautions psychologists about the limitations of assessment tools.

A) ABA's

B) APA's

C) AMA's

D) ADA's

Q5) FRE ____ describes whether basis for the testimony is adequate.

A) 700

B) 701

C) 702

D) 703

To view all questions and flashcards with answers, click on the resource link above. Page 19

Turn static files into dynamic content formats.

Create a flipbook
Cybersecurity Fundamentals Exam Preparation Guide - 768 Verified Questions by Quizplus - Issuu