II0-001 Exam Questions
228 real II0-001 exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1
In order to prevent footprinting of an environment, one method that is effective is:
- Question #2
Because of overlapping security domains, it is impossible to have two perimeter security devices (firewalls) in successive layers.
- Question #3
The "Stealth Rule" in a perimeter security device prevents it from being footprinted.
- Question #4
If a file is properly encrypted, it can not be read except by the file owner.
- Question #5
When electronic evidence has been encrypted, the best method of discovery is:
- Question #6
What method can be used to detect the use of rogue servers providing services such as illegal software distribution, music files, pornography in an environment?
- Question #7
How many port/services are available using the TCP/IP suite?
- Question #8
A rule that allows any traffic from the trusted network through to untrusted networks is a security risk because:
- Question #9
For many ISPs, placing a network protocol sniffer in their infrastructure allows them to be very effective in support law enforcement during an investigation.
- Question #10
A syslog server and a protocol sniffer perform the same basic function.
- Question #11
When investigating a malicious attack sourced from the Internet, the investigator would look for forensic evidence in:
- Question #12
During a brute force attack, an active trace may be initiated using what tool?
- Question #13
Many malicious attacks are sourced to ISP dial up accounts, what makes this type of attack source a challenge for an investigator?
- Question #14
A "listening post" usually refers to:
- Question #15
During an incident, an incident response team springs into action. What is one of the first steps the team will take?
- Question #16
As a private investigator, you are not required to report most crimes discovered during your investigation unless the crime is in the planning stages, is child exploitation, or iss...
- Question #17
The common practices of legal requirements of record retention is dependant upon the type of information.
- Question #18
When a hard drive is formatted. (other than partition table, boot record, root directory and other system areas) what character would be found over the entire disk
- Question #19
What is the currently accepted hashing algorithm used for digital signature standard (DSS) based on NIST documentation
- Question #20
The following log is an example of :
- Question #21
Some disk imaging techniques miss "hidden" or divergent operating system partitions. A method of ensuring that no partitions are missed during imaging is by:
- Question #22
An inode table is to Linux as:
- Question #23
When auditing log files for system discrepancies, why is NTP important?
- Question #24
What is the correct command in a Linux 6.0 or later system to check the hash of a hard drive attached to the system?
- Question #25
Which of the following is included in the ISFA code of Ethics?
- Question #26
There are a total of 7 ethics statements in the ISFA code of Ethics
- Question #27
Under the ISFA Code of Ethics, a CIFI may not disclose information gathered during an investigation except under duress.
- Question #28
According to the ISFA Code of Ethics, an ISFA member must conduct themselves with professionalism, honor, and honesty.
- Question #29
As a private CIFI investigator, you are not required to conduct your investigations according to the law as you are not an agent of the state.
- Question #30
Regardless of whether an incident is malicious or accidental, the impact is the same.
- Question #31
In certain circumstances, it is necessary to penetrate remote systems (un-owned) in order to retrieve logs for evidence. If properly hashed at the remote site and once retrieved, w...
- Question #32
Stone stepping or server hopping is the technique of hackers to mask their source identity.
- Question #33
SMTP headers in an email will contain the original host address even if that address is a reserved address space and therefore can reveal internal information of a network layout.
- Question #34
What term refers to the technique of utilizing inferential evidence and social engineering in order to identify a subject of an investigation when search warrant or subpoena is una...
- Question #35
An investigator's notes can be subpoena by opposing counsel if not protected by attorney privilege.
- Question #36
Auditing need only be completed prior to an incident. The forensics investigation following will provide more than adequate auditing information.
- Question #37
The following is an example of: Version: PGP 8.0 mQGiBD1ik/MRBAD10IH/NQZ1Qsh6ixloDYVoWZJd2raAWjmnT5PCj6VbDO2PIdpZ bStv5wRYiZTItiYhO2o0EHfhFnJTWPY01joUXT8PRRa5fYL9A1BSkJOwN8hupRiO t...
- Question #38
The Incident Response Team Leader (or IRT Leader) has more authority during an incident than:
- Question #39
If a private investigator determines a crime has been committed and contacts law enforcement to investigate, the investigation still is under the jurisdiction of the private invest...
- Question #40
The following graphic is an example of what tool?
- Question #41
The following tool output example can be used in a dynamic investigation. What will it demonstrate? Active Connections Proto Local Address Foreign Address StateTCP local:epmap 90.2...
- Question #42
Which of the following are not principles in the ISFA code of ethics?
- Question #43
A honeypot may be configured to allow a continuation of a malicious attack while preserving the target of the attack.
- Question #44
The Foreign Intelligence Surveillance Act (FISA) of 1978 was primarily dealing with:
- Question #45
The Counterfeit Access Device and Computer Fraud and Abuse Act of 1986 was designed to do the following except:
- Question #46
The Wiretap and Stored Communications Access Act adds an additional component to previous laws by:
- Question #47
The Computer Fraud and Abuse Act applies to:
- Question #48
The USA Patriot Act of 2001 has a significant impact to the investigation of computer related crime with stiffer penalties and greater latitude in investigation by law enforcement....
- Question #49
The following methods are used to ensure an employer is not violating Title III provisions for employee privacy except:
- Question #50
The following are laws that have impact on electronic media and/or investigations: