IISFA Certified Information Forensics Investigator(CIFI) - II0-001 模擬練習
Logs should be kept:
正解: C
It is critical for an investigator to understand counter measures and secure design fully in order to:
正解: A
What is the correct command in a Linux 6.0 or later system to check the hash of a hard drive attached to the system?
正解: A
Which header is not used to determine the source of an email?
正解: A
A Syslog server provides:
正解: C
In many cases, the trail of an investigation begins with an audit of:
正解: B
Added "Received:" headers often include bogus information. All of the following items except one, is usually incomplete:
正解: B
In order to prevent footprinting of an environment, one method that is effective is:
正解: C
According to the ISFA Code of Ethics, an ISFA member must conduct themselves with professionalism, honor, and honesty.
正解: B
What technique of layered security design will allow for both investigation and recovery after an incident?
正解: B
The following is an example of:
Version: PGP 8.0
mQGiBD1ik/MRBAD10IH/NQZ1Qsh6ixloDYVoWZJd2raAWjmnT5PCj6VbDO2PIdpZ
bStv5wRYiZTItiYhO2o0EHfhFnJTWPY01joUXT8PRRa5fYL9A1BSkJOwN8hupRiO
teCOew6c1WYetshrV0CgpLvc2cmHkelS1IQSwtnCPlikFIqfKlzHTpYSIwCg//PV
Lzn4A0/hQ+4zTp+7fz7bYTsEAKhDWdzWzG8FCyfK5OTygb+CYkbZt9rgF5YJsDCl
E84joc0g4uGwNanHmoxYJnq74YUuhCK5sWQaK0HVYIXEVQrapmgADSyLCkez2+Jy
f696D0ju+RDj3XXyhIH32s4avT+VLpYVBEWdf5xmMe7ENhiMTzsxqnp/KDbD8MH3
0AfGBADFXPeNkSXrODO/KGIEuSH69+xxuiqnFDQ68lIDlnhV9nvzP6x36uiA97hp
QJ1nx3GLMrUgndPiMSMeOWx++nYOXFl34g0Dynu/unvL6yAg8HHGolX0Ms++QSQE
7T1ZnDRqj/li2C84aww8prQA5hQVmezgZ2zroDt6+tpq7uBvSLRASmFtZXMgQS4g
TW9vcmUsIENJU1NQL1NTQ1AsIFNyLiBQYXJ0bmVyIDxqbW9vcmVAdDNpc2VjdXJp
dHkuY29tPokATgQQEQIADgUCPWKT8wQLAwIBAhkBAAoJEDELFLfA5U0IllYAoPsm
ZYb7Hyuk9KPmUGGo/g0r0L+OAKDQPx8OWkRliRu358lZaLGpH9HaW7kDDQQ9YpPz
EAwAzB13VyQ4SuLE8OiOE2eXTpITYfbb6yUOF/32mPfIfHmwch04dfv2wXPEgxEm
K0Ngw+P
Version: PGP 8.0
mQGiBD1ik/MRBAD10IH/NQZ1Qsh6ixloDYVoWZJd2raAWjmnT5PCj6VbDO2PIdpZ
bStv5wRYiZTItiYhO2o0EHfhFnJTWPY01joUXT8PRRa5fYL9A1BSkJOwN8hupRiO
teCOew6c1WYetshrV0CgpLvc2cmHkelS1IQSwtnCPlikFIqfKlzHTpYSIwCg//PV
Lzn4A0/hQ+4zTp+7fz7bYTsEAKhDWdzWzG8FCyfK5OTygb+CYkbZt9rgF5YJsDCl
E84joc0g4uGwNanHmoxYJnq74YUuhCK5sWQaK0HVYIXEVQrapmgADSyLCkez2+Jy
f696D0ju+RDj3XXyhIH32s4avT+VLpYVBEWdf5xmMe7ENhiMTzsxqnp/KDbD8MH3
0AfGBADFXPeNkSXrODO/KGIEuSH69+xxuiqnFDQ68lIDlnhV9nvzP6x36uiA97hp
QJ1nx3GLMrUgndPiMSMeOWx++nYOXFl34g0Dynu/unvL6yAg8HHGolX0Ms++QSQE
7T1ZnDRqj/li2C84aww8prQA5hQVmezgZ2zroDt6+tpq7uBvSLRASmFtZXMgQS4g
TW9vcmUsIENJU1NQL1NTQ1AsIFNyLiBQYXJ0bmVyIDxqbW9vcmVAdDNpc2VjdXJp
dHkuY29tPokATgQQEQIADgUCPWKT8wQLAwIBAhkBAAoJEDELFLfA5U0IllYAoPsm
ZYb7Hyuk9KPmUGGo/g0r0L+OAKDQPx8OWkRliRu358lZaLGpH9HaW7kDDQQ9YpPz
EAwAzB13VyQ4SuLE8OiOE2eXTpITYfbb6yUOF/32mPfIfHmwch04dfv2wXPEgxEm
K0Ngw+P
正解: A
IP-based denial- of-service (DOS) and fragmented packet (TearDrop) attacks can be identified by looking at the packet headers as they travel across a network. This type of attack can be quickly identified by a network-based IDS looking at the packet stream in real-time. Why is it that the Host-Based IDS miss these attacks?
正解: B