Digital Forensics Final Quiz

25 July 2022
4.7 (114 reviews)
100 test answers

Unlock all answers in this set

Unlock answers (96)
question
People need ethics to help maintain their balance, especially in difficult and contentious situations. β€’ A. True β€’ B. False
answer
A. True
question
In the United States, there's no state or national licensing body for computer forensics examiners. β€’ A. True β€’ B. False
answer
A. True
question
Experts should be paid in full for all previous work and for the anticipated time required for testimony. β€’ A. True β€’ B. False
answer
A. True
question
Expert opinions cannot be presented without stating the underlying factual basis. β€’ A. True β€’ B. False
answer
B. False
question
The American Bar Association (ABA) is a licensing body. β€’ A. True β€’ B. False
answer
B. False
question
The most important laws applying to attorneys and witnesses are the ____. β€’ A. professional ethics β€’ B. rules of ethics β€’ C. rules of evidence β€’ D. professional codes of conduct
answer
C. rules of evidence
question
Computer forensics examiners have two roles: fact witness and ____ witness. β€’ A. professional β€’ B. direct β€’ C. discovery β€’ D. expert
answer
D
question
Attorneys search ____ for information on expert witnesses. β€’ A. cross-examination banks β€’ B. examination banks β€’ C. deposition banks β€’ D. disqualification banks
answer
C
question
____ questions can give you the factual structure to support and defend your opinion. β€’ A. Rapid-fire β€’ B. Hypothetical β€’ C. Setup β€’ D. Compound
answer
B
question
FRE ____ describes whether the expert is qualified and whether the expert opinion can be helpful. β€’ A. 702 β€’ B. 703 β€’ C. 704 β€’ D. 705
answer
A
question
FRE ____ describes whether basis for the testimony is adequate. β€’ A. 700 β€’ B. 701 β€’ C. 702 β€’ D. 703
answer
D
question
The ____ has stated that, unlike attorneys, expert witnesses do not owe a duty of loyalty to their clients. β€’ A. HTCIA β€’ B. IACIS β€’ C. ISFCE β€’ D. ABA
answer
D
question
____ offers the most comprehensive regulations of any professional organization and devote an entire section to forensics activities. β€’ A. AMA's law β€’ B. ABA's Model Rule β€’ C. ABA's Model Codes β€’ D. APA's Ethics Code
answer
D
question
On NTFS drives, Unicode values are how many bits in length? β€’ A. 8 bits β€’ B. 32 bits β€’ C. 16 bits β€’ D. 64 bits
answer
C
question
What are the first 8 bits of a Unicode value used for? β€’ A. file type identification β€’ B. font selection β€’ C. character hexidecimal values β€’ D. language identification
answer
C
question
What do the last 8 bits of a Unicode value represent? β€’ A. language identification β€’ B. character hexadecimal values β€’ C. file type identification β€’ D. font selection
answer
B
question
When converting plain text to hexadecimal for use with ProDiscover, you need to place ____________ between each character's hexadecimal values. β€’ A. space (A0) values β€’ B. blank (00) values β€’ C. null (FF) values β€’ D. null (00) values
answer
D
question
In what court case did the court summarize the process of determining whether an expert should be disqualified because of previous contact with an opposing party? β€’ A. Tidemann v. Toshiba Corp β€’ B. Wang Laboratories, Inc. v. Toshiba Corp β€’ C. Tidemann v. Nadler Golf Car Sales, Inc. β€’ D. Hewlett-Packard Co. v. EMC Corp
answer
B
question
What Unicode value is used to identify the latin alphabet? β€’ A. 0x00 β€’ B. 0xF8 β€’ C. 0xAB β€’ D. 0x01
answer
A
question
Currently, expert witnesses testify in more than __ percent of trials. β€’ A. 55 β€’ B. 80 β€’ C. 92 β€’ D. 76
answer
B
question
People who fear having their ______________ acts revealed feel as though they must protest the ________________ acts of others being revealed. β€’ A. legal β€’ B. improper β€’ C. secret β€’ D. public
answer
A
question
The purpose of requesting the ________________ is to deter attorneys from communicating with you solely for the purpose of disqualifying you. β€’ A. case β€’ B. retainer β€’ C. juror list β€’ D. evidence
answer
A
question
Which of the following options would represent a valid retainer? β€’ A. 2 to 8 hours of your usual billable rate β€’ B. a verbal agreement β€’ C. complete discussion of an ongoing case β€’ D. dissemination of evidence
answer
A
question
Before allowing an attorney to describe any case details, determine who the parties are to reduce the possibility of a _______________. β€’ A. collaberation β€’ B. conflict β€’ C. mistrial β€’ D. contradiction
answer
B
question
A consultant who doesn't testify can earn a ____________________ for locating testifying experts or investigative leads. β€’ A. contingency fee β€’ B. retainer β€’ C. stake in a case β€’ D. reprimand
answer
A
question
1 of 25 0.05 Points As an expert witness, you have opinions about what you have found or observed. A. True B. False
answer
A
question
2 of 25 0.05 Points You should create a formal checklist of your procedures that's applied to all your cases or include such a checklist in your report. A. True B. False
answer
B
question
3 of 25 0.05 Points As a standard practice, collect evidence and record the tools you used in designated file folders or evidence containers. A. True B. False
answer
A
question
4 of 25 0.05 Points Like a job resume, your CV should be geared for a specific trial. A. True B. False
answer
B
question
5 of 25 0.05 Points Part of what you have to deliver to the jury is a person they can trust to help them figure out something that's beyond their expertise. A. True B. False
answer
A
question
6 of 25 0.05 Points When cases go to trial, you as a forensics examiner can play one of ____ roles. A. 2 B. 3 C. 4 D. 5
answer
A
question
7 of 25 0.05 Points When you give ____ testimony, you present this evidence and explain what it is and how it was obtained. A. technical/scientific B. expert C. lay witness D. deposition
answer
A
question
8 of 25 0.05 Points Validate your tools and verify your evidence with ____ to ensure its integrity. A. hashing algorithms B. watermarks C. steganography D. digital certificates
answer
A
question
9 of 25 0.05 Points For forensics specialists, keeping the ____ updated and complete is crucial to supporting your role as an expert and showing that you're constantly enhancing your skills through training, teaching, and experience. A. testimony B. CV C. examination plan D. deposition
answer
B
question
10 of 25 0.05 Points If your CV is more than ____ months old, you probably need to update it to reflect new cases and additional training. A. 2 B. 3 C. 4 D. 5
answer
B
question
11 of 25 0.05 Points ____ is a written list of objections to certain testimony or exhibits. A. Defendant B. Empanelling the jury C. Plaintiff D. Motion in limine
answer
D
question
12 of 25 0.05 Points Regarding a trial, the term ____ means rejecting potential jurors. A. voir dire B. rebuttal C. strikes D. venireman
answer
C
question
13 of 25 0.05 Points ____ from both plaintiff and defense is an optional phase of the trial. Generally, it's allowed to cover an issue raised during cross-examination. A. Rebuttal B. Plaintiff C. Closing arguments D. Opening statements
answer
A
question
14 of 25 0.05 Points If a microphone is present during your testimony, place it ____ to eight inches from you. A. 3 B. 4 C. 5 D. 6
answer
D
question
15 of 25 0.05 Points Jurors typically average just over 12 years of education and an eighth-grade reading level.
answer
12
question
16 of 25 0.05 Points ____ is an attempt by opposing attorneys to prevent you from serving on an important case. A. Conflict of interest B. Warrant C. Deposition D. Conflicting out
answer
D
question
17 of 25 0.05 Points ____ evidence is evidence that exonerates or diminishes the defendant's liability. A. Rebuttal B. Plaintiff C. Inculpatory D. Exculpatory
answer
D
question
18 of 25 0.05 Points You provide ____ testimony when you answer questions from the attorney who hired you. A. direct B. cross C. examination D. rebuttal
answer
A
question
19 of 25 0.05 Points The ____ is the most important part of testimony at a trial. A. cross-examination B. direct examination C. rebuttal D. motions in limine
answer
B
question
20 of 25 0.05 Points Generally, the best approach your attorney can take in direct examination is to ask you ____ questions and let you give your testimony. A. setup B. open-ended C. compound D. rapid-fire
answer
B
question
21 of 25 0.05 Points Leading questions such as "Isn't it true that forensics experts always destroy their handwritten notes?" are referred to as ____ questions. A. hypothetical B. attorney C. setup D. nested
answer
C
question
22 of 25 0.05 Points Sometimes opposing attorneys ask several questions inside one question; this practice is called a ____ question. A. leading B. hypothetical C. compound D. rapid-fire
answer
C
question
23 of 25 0.05 Points A ____ differs from a trial testimony because there is no jury or judge. A. rebuttal B. plaintiff C. civil case D. deposition
answer
D
question
24 of 25 0.05 Points There are two types of depositions: ____ and testimony preservation. A. examination B. discovery C. direct D. rebuttal
answer
B
question
25 of 25 0.05 Points Discuss any potential problems with your attorney ____ a deposition. A. before B. after C. during D. during direct examination at
answer
A
question
1 of 25 0.05 Points A report can provide justification for collecting more evidence and be used at a probable cause hearing. A. True B. False
answer
A
question
2 of 25 0.05 Points Expert witnesses are not required to submit a written report for civil cases. A. True B. False
answer
B
question
3 of 25 0.05 Points Technical terms, if included in a report, should be defined in ordinary language such that lawyers, judges, and jurors can understand them. A. True B. False
answer
A
question
4 of 25 0.05 Points An expert's opinion is governed by FRCP, Rule 26, and the corresponding rule in many states. A. True B. False
answer
B
question
5 of 25 0.05 Points Specially trained system and network administrators are often a CSP's first responders. A. True B. False
answer
A
question
6 of 25 0.05 Points A report using the _________________ system divides material into sections and restarts numbering with each main section. A. numerically ordered B. hierarchical C. decimal numbering D. number formatted
answer
C
question
7 of 25 0.05 Points When using the PassMark software to find forensic information in e-mails, messages that appear to be suspicious should be flagged __________. A. Yellow B. Green C. Red D. Orange
answer
A
question
8 of 25 0.05 Points The report generator in ProDiscover defaults to ______________________, which can be opened by most word processors. A. HyperText Markup Language (HTML) B. Rich Text Format (RTF) C. Extensible Markup Language (XML) D. Microsoft Word document format
answer
B
question
9 of 25 0.05 Points When writing a report, group related ideas and sentences into ___________________, A. chapters B. sections C. paragraphs D. separate reports
answer
C
question
10 of 25 0.05 Points If a preliminary report is written, destroying the preliminary report after the final report is complete could be considered ______________. A. proper data security B. spoliation C. beneficial D. necessary
answer
B
question
11 of 25 0.05 Points How many words should be in the abstract of a report? A. 50 to 100 words B. 100 to 150 words C. 150 to 200 words D. 200 to 250 words
answer
C
question
12 of 25 0.05 Points The ________________ section of a report starts by referring to the report's purpose, states the main points, draws conclusions, and possibly renders an opinion. A. body B. conclusion C. appendix D. reference
answer
B
question
13 of 25 0.05 Points What rule of the Federal Rules of Civil Procedure requires that parties who anticipate calling an expert witness to testify must provide a copy of the expert's written report that includes all opinions, the basis for the opinions, and the information considered in coming to those opinions? A. rule 24 B. rule 35 C. rule 36 D. rule 26
answer
D
question
14 of 25 0.05 Points Which type of report typically takes place in an attorney's office? A. Examination Plan B. Written Report C. Preliminary Report D. Verbal Report
answer
D
question
15 of 25 0.05 Points Lawyers may request _________________ of previous testimony by their own potential experts to ensure that the experts haven't previously testified to a contrary position. A. warrants B. transcripts C. subpoenas D. evidence
answer
B
question
16 of 25 0.05 Points The rule that states that testimony is inadmissible unless it is "testimony deduced from a well-recognized scientific principle or discovery; the thing from which the deduction is made must be sufficiently established to have gained general acceptance in the particular field in which it belongs", was established in what court case? A. Daubert v. Merrell Dow Pharmaceuticals, Inc. B. Smith v. United States C. Frye v. United States D. Dillon v. United States
answer
C
question
17 of 25 0.05 Points As with any research paper, write the ___________________ last. A. appendix B. body C. acknowledgements D. abstract
answer
D
question
18 of 25 0.05 Points The _________________ numbering system is often used in legal pleadings. Each Roman numeral represents a major aspect of the report, and each Arabic numeral is an important piece of supporting information. A. decimal B. ordered-sequential C. legal-sequential D. reverse-order
answer
C
question
19 of 25 0.05 Points How you format _____________ is less important than being consistent in applying formatting. A. words B. text C. paragraphs D. sections
answer
B
question
20 of 25 0.05 Points In addition to opinions and exhibits, the ______________ must specify fees paid for the expert's services and list all other civil or ciminal cases in which the expert has testified. A. verbal report B. informal report C. written report D. preliminary report
answer
C
question
21 of 25 0.05 Points An ___________________ is a document that serves as a guideline for knowing what questions to expect when you're testifying. A. testimony procedure B. examination plan C. planned questionairre D. testimony excerpt
answer
B
question
22 of 25 0.05 Points An expert's opinion is governed by ________________ and the corresponding rule in many states. A. FRE, Rule 705 B. FRE, Rule 507 C. FRCP 26 D. FRCP 62
answer
A
question
23 of 25 0.05 Points _______________ is the process of opposing attorneys seeking information from each other. A. Subpoena B. Warranting C. Discovery D. Digging
answer
C
question
24 of 25 0.05 Points If a report is long and complex, you should include a(n) _____________. A. appendix B. abstract C. glossary D. table of contents
answer
B
question
25 of 25 0.05 Points __________________ means the tone of language you use to address the reader. A. Style B. Format C. Outline D. Prose
answer
A
question
1 of 25 0.05 Points The Internet is the successor to the Advanced Research Projects Agency Network (ARPANET). A. True B. False
answer
A
question
2 of 25 0.05 Points A search warrant can be used in any kind of case, either civil or criminal. A. True B. False
answer
B
question
3 of 25 0.05 Points Specially trained system and network administrators are often a CSP's first responders. A. True B. False
answer
A
question
4 of 25 0.05 Points The law requires search warrants to contain specific descriptions of what's to be seized. For cloud environments, the property to be seized usually describes physical hardware rather than data, unless the CSP is a suspect. A. True B. False
answer
A
question
5 of 25 0.05 Points In the United States, the Electronic Communications Privacy Act (ECPA) describes 5 mechanisms the government can use to get electronic information from a provider. A. True B. False
answer
A
question
6 of 25 0.05 Points Metadata in a prefetch file contains an application's _____________ times in UTC format and a counter of how many times the application has run since the prefect file was created. A. startup / access B. log event C. ACL D. MAC
answer
D
question
7 of 25 0.05 Points The __________________________ is an organization that has developed resource documentation for CSPs and their staff. It provides guidance for privacy agreements, security measures, questionnaires, and more. A. OpenStack Framework Alliance B. vCloud Security Advisory Panel C. Cloud Security Alliance D. Cloud Architecture Group
answer
C
question
8 of 25 0.05 Points Which of the following is NOT a service level for the cloud? A. Platform as a service B. Infrastructure as a service C. Virtualization as a service D. Software as a service
answer
C
question
9 of 25 0.05 Points What cloud application offers a variety of cloud services, including automation and CRM, cloud application development, and Web site marketing? A. Amazon EC2 B. IBM Cloud C. Salesforce D. HP Helion
answer
C
question
10 of 25 0.05 Points A ________________ is written by a judge to compel someone to do or not do something, such as a CSP producing user logon activities. A. court order B. temporary restraining order C. warrant D. subpoena
answer
A
question
11 of 25 0.05 Points To reduce the time it takes to start applications, Microsoft has created __________ files, which contain the DLL pathnames and metadata used by applications. A. temp B. cache C. config D. prefetch
answer
D
question
12 of 25 0.05 Points What information below is not something recorded in Google Drive's snapshot.db file? A. modified and created times B. URL pathnames C. file access records D. file SHA values and sizes
answer
D
question
13 of 25 0.05 Points With cloud systems running in a virtual environment, _______________ can give you valuable information before, during, and after an incident. A. carving B. live acquisition C. RAM D. snapshot
answer
D
question
14 of 25 0.05 Points Which of the following is not one of the five mechanisms the government can use to get electronic information from a provider? A. search warrants B. subpoenas C. court orders D. seizure order
answer
D
question
15 of 25 0.05 Points Which is not a valid method of deployment for a cloud? A. community B. public C. targeted D. private
answer
C
question
16 of 25 0.05 Points The ______________ tool can be used to bypass a virtual machine's hypervisor, and can be used with OpenStack. A. OpenForensics B. FROST C. WinHex D. ARC
answer
B
question
17 of 25 0.05 Points What cloud service listed below provides a freeware type 1 hypervisor used for public and private clouds? A. HP Helion B. Amazon EC2 C. XenServer and XenCenter Windows Management Console D. Cisco Cloud Computing
answer
C
question
18 of 25 0.05 Points Select the folder below that is most likely to contain Dropbox files for a specific user: A. C:UsersusernameAppDataDropbox B. C:Dropbox C. C:UsersDropbox D. C:UsersusernameDropbox
answer
D
question
19 of 25 0.05 Points A _________________ is a tool with application programming interfaces (APIs) that allow reconfiguring a cloud on the fly; it's accessed through the application's Web interface. A. configuration manager B. management plane C. backdoor D. programming language
answer
B
question
20 of 25 0.05 Points The __________________ Dropbox file stores information on shared directories associated with a Dropbox user account and file transfers between Dropbox and the client's system. A. read_filejournal B. filetx.log C. filecache.dbx D. filecache.dll
answer
C
question
21 of 25 0.05 Points In a prefetch file, the application's last access date and time are at offset _______________. A. 0x80 B. 0x88 C. 0xD4 D. 0x90
answer
D
question
22 of 25 0.05 Points At what offset is a prefetch file's create date & time located? A. 0x88 B. 0x80 C. 0x98 D. 0x90
answer
B
question
23 of 25 0.05 Points Which of the following is not a valid source for cloud forensics training? A. Sans Cloud Forensics with F-Response B. A+ Security C. INFOSEC Intitute D. (ISC)2 Certified Cyber Forensics Professional
answer
B
question
24 of 25 0.05 Points Where is the snapshot database created by Google Drive located in Windows? A. C:Program FilesGoogleDrive B. C:UsersusernameAppDataLocalGoogleDrive C. C:UsersusernameGoogleGoogle Drive D. C:GoogleDrive
answer
B
question
25 of 25 0.05 Points The Google drive file _________________ contains a detailed list of a user's cloud transactions. A. loggedtransactions.log B. sync_log.log C. transact_user.db D. history.db
answer
B