II0-001 Exam Questions
228 real II0-001 exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #101
A well rounded information security program should include:
- Question #102
BCP consists of:
- Question #103
The best type of evidence to have would be:
- Question #104
The four steps in evidence handling in the proper order are:
- Question #105
An event is considered an incident when it meets or exceed which standard?
- Question #106
Training employees on Incident Response Teams authority is critical because:
- Question #107
All of the following are states a file cluster can exist in an Microsoft XP operating system except:
- Question #108
For proper investigative methods to be valid, they must:
- Question #109
Slack space is space not used within a partition of a hard drive.
- Question #110
To identify which partition in the MBR is active, you should look for:
- Question #111
The MBR typically starts at sector:
- Question #112
An expert report differs from an investigative report in which of the following ways?
- Question #113
Which of the following methods will not ensure the admissibility of electronic evidence (in terms of collection)?:
- Question #114
In an information forensics investigation, when opposing litigants have an expert, it is acceptable to QUESTION NO: the integrity of the expert?
- Question #115
An effective method of remotely collecting logs (as evidence) is to TFTP the files and then hash them.
- Question #116
Disk arrays are impossible to correctly image as you are unable to get correct drive geometry.
- Question #117
When performing a forensic lockdown, the investigator is ensuring which of the following?:
- Question #118
According to IIFS100, the following is the proper sequence for image verification:
- Question #119
Compression of collected evidence can't be utilized because:
- Question #120
A copy of the MBR is located on the center of a hard drive?
- Question #121
A Microsoft MFT has a duplicate copy for recovery from corruption of the primary MFT?
- Question #122
Resident attributes refers to file information, in an NTFS file system, that resides in the MFT.
- Question #123
Which of the following represents the data found at a NTFS hard drive, and lasts for 3 bytes?
- Question #124
What Federal rule requires that all opinions of a witness giving expert testimony in civil litigation be written and signed; and the basis and reasoning therefore be formatted to i...
- Question #125
A forensic investigator must be familiar with the following:
- Question #126
When collecting a desktop computer system from a crime scene that is powered on and operating what is the correct way of shutting the system down?
- Question #127
There are two types of evidence: what are they?
- Question #128
Which of the following is not related to Rules of Evidence?
- Question #129
Which of the following is NOT a necessary step when documenting the crime scene?
- Question #130
After a forensics investigator seizes and transports the computer, what is the next step?
- Question #131
The process of evidence handling, protection of the evidence and providing accountability for who handled the evidence during the investigation is referred to as what?
- Question #132
What prohibits the government from performing unreasonable searches without having probable cause?
- Question #133
There are several types of evidence that can be used in a trial. Which type of evidence listed below provides the most reliability?
- Question #134
When handling evidence, which of the following is not a common guideline?
- Question #135
Copies of original evidence, such as disks and other media, are considered what in court unless they are collected during the normal course of business operations?
- Question #136
Electronic evidence is easily
- Question #137
The Best Evidence Rule is
- Question #138
An investigator should treat each incident
- Question #139
You can show that the evidence was not tampered with by
- Question #140
The investigator needs to think about reporting
- Question #141
A deposition is a method of
- Question #142
The investigator must be ethical
- Question #143
The measure of a magnetic media's ability to retain data is the media's:
- Question #144
The MD5 hashing algorithm produces a number (message digest) of what size regardless of how large the submitted source data.
- Question #145
The Privacy Protection Act of 1980
- Question #147
The 1st sector of a hard disk is sometimes called:
- Question #148
An advanced application of making use of proxies to hide an IP that makes tracing virtually impossible is called:
- Question #149
The data structure for DNS queries contains all of the following except?
- Question #150
In an email header, what information should never be trusted?
- Question #151
Information that is included in an email header includes all of the following except: