Question 211
Examination of a computer by a technically unauthorized person will almost always result in:
Question 212
Which of the following Linux command searches through the current processes and lists the process IDs those match the selection criteria to stdout?
Question 213
You have been asked to investigate the possibility of computer fraud in the finance department of a company. It is suspected that a staff member has been committing finance fraud by printing cheques that have not been authorized. You have exhaustively searched all data files on a bitmap image of the target computer, but have found no evidence. You suspect the files may not have been saved. What should you examine next in this case?
Question 214
Lance wants to place a honeypot on his network. Which of the following would be your recommendations?
Question 215
An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?
