Question 16
Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage:
Question 17
Which of the following is a technique used by attackers to make a message difficult to understand through the use of ambiguous language?
Question 18
The sign(s) of the presence of malicious code on a host infected by a virus which is delivered via e-mail could
be:
be:
Question 19
John is performing a memory dump analysis in order to find traces of malware. He has employed Volatility tool in order to achieve his objective.
Which of the following volatility framework command she will use in order to analyze the running process from the memory dump?
Which of the following volatility framework command she will use in order to analyze the running process from the memory dump?
Question 20
Sam, an employee of a multinational company, sends emails to third-party organizations with a spoofed email address of his organization.
How can you categorize this type of incident?
How can you categorize this type of incident?
