Question 201

Which of the following tool can the investigator use to analyze the network to detect Trojan activities?
  • Question 202

    Jason has set up a honeypot environment by creating a DMZ that has no physical or logical access to his production network. In this honeypot, he has placed a server running Windows Active Directory. He has also placed a Web server in the DMZ that services a number of web pages that offer visitors a chance to download sensitive information by clicking on a button. A week later, Jason finds in his network logs how an intruder accessed the honeypot and downloaded sensitive information. Jason uses the logs to try and prosecute the intruder for stealing sensitive corporate information. Why will this not be viable?
  • Question 203

    Fill In the missing Master Boot Record component.
    1. Master boot code
    2. Partition table
    3._______________
  • Question 204

    Chloe is a forensic examiner who is currently cracking hashed passwords for a crucial mission and hopefully solve the case. She is using a lookup table used for recovering a plain text password from cipher text; it contains word list and brute-force list along with their computed hash values. Chloe Is also using a graphical generator that supports SHA1.
    a. What password technique is being used?
    b. What tool is Chloe using?
  • Question 205

    Corporate investigations are typically easier than public investigations because: