II0-001 Exam Questions
228 real II0-001 exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #152
During a message processing, headers will be added to the message at all times except?
- Question #153
All are common email headers except?
- Question #154
In context to email headers, reverse DNS is used to verify
- Question #155
The single most valuable forgery protection in the Received: headers is the information logged by the:
- Question #156
A trick used by forgers is to:
- Question #157
Which of the following is not an internet email protocol?
- Question #158
Which email protocol provides remote filing capabilities?
- Question #159
Which header is not used to determine the source of an email?
- Question #160
Widely known tricks used to forge common headers consist of the following except:
- Question #161
Clues that a "Received:" header has been forged include all but one of the following:
- Question #162
Added "Received:" headers often include bogus information. All of the following items except one, is usually incomplete:
- Question #163
Generally, which header is used to reveal reliable information from forged emails:
- Question #164
Which tool is used to confirm the name or IP address of an Internet host:
- Question #165
In the OSI stack, which layer is associated with TCP transmissions?
- Question #166
The result of an attack Traceback can be characterized by these three parameters, the degree of which determines success:
- Question #167
A SYN attack exploits what aspect of TCP communications?
- Question #168
Which method is NOT regarded as a prevention technique for IP spoofing:
- Question #169
Firewalls are an excellent source of:
- Question #170
What technique of layered security design will allow for both investigation and recovery after an incident?
- Question #171
If a CIFI violates the ISFA code of Ethics, her CIFI certification can be immediately revoked.
- Question #172
The 1st amendment allows hackers to exercise free speech by altering content on websites to express opposing viewpoints.
- Question #173
The term "Browser Artifacts" refer to:
- Question #174
All of the following are methods of auditing except:
- Question #175
In selecting Forensic tools for collecting evidence in the investigation of a crime the standard for authenticating computer records is:
- Question #176
"Interesting data" is:
- Question #177
Social engineer is legal in the United States, Great Britain, Canada, and Australia as long as the social engineer does not:
- Question #178
Free space is unallocated file space within a partition.
- Question #179
Slack space is the space in a file cluster that is not actively used by the file.
- Question #180
It is possible to place IDS in a switched environment effectively with the use of a Spanning Port
- Question #181
Which one of the following is NOT true?
- Question #182
The IISFA will revoke the certification of a CIFI if an ethic violation of a CIFI is reported and confirmed.
- Question #183
The MFT contains records with the following information
- Question #184
The MFT File is a physical file on the disk that:
- Question #185
The MBR is easily identified on a Windows XP system by:
- Question #186
Embedding a serial number or watermark into a data file is known as:
- Question #187
What is the difference between a zombie host and a reflector host?
- Question #188
The major disadvantage to techniques that attempt to mark IP packets as they move
- Question #189
In normal operation, a host receiving packets can determine their source by direct examination of the source address field in the:
- Question #190
One caution an investigator should take when examining the source of a network attack is:
- Question #191
Stream comparison used as a Traceback technique focuses on what two factors?
- Question #192
To perform a successful traceback, the two most prominent problems that need to be solved are locating the source of IP packets and:
- Question #193
The most important network information that should be observed from the logs during a Traceback is the intruder IP address, the victim IP address, the victim port, protocol informa...
- Question #194
A new protocol that is designed to aid in intrusion protection and IP tracebacks is known as:
- Question #195
Tracebacks are difficult to perform in a Distributed Denial of Service attack because:
- Question #196
A Distributed Denial of Service attack has just occurred using reflectors. What are the implications in terms of tracing the attack back?
- Question #197
Auditing that discovers evidence of a crime can't be used as evidence because:
- Question #198
The following are all keyloggers except:
- Question #199
The following are all keyloggers except:
- Question #200
Which of the following is an effective method for completing a disk image quickly?
- Question #201
Keyloggers are impossible to detect.