100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
CHFI Study Questions with Correct Answers 100% Pass $13.49
Add to cart

Exam (elaborations)

CHFI Study Questions with Correct Answers 100% Pass

 0 purchase
  • Course
  • CHFI
  • Institution
  • CHFI

CHFI Study Questions with Correct Answers 100% Pass When an investigator contacts by telephone the domain administrator or controller listed by a Who is lookup to request all e-mails sent and received for a user account be preserved, what U.S.C. statute authorizes this phone call and obligates...

[Show more]

Preview 4 out of 43  pages

  • March 9, 2025
  • 43
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • CHFI
  • CHFI
avatar-seller
KatelynWhitman
CHFI Study Questions with Correct
Answers 100% Pass


When an investigator contacts by telephone the domain administrator or

controller listed by a Who is lookup to request all e-mails sent and received

for a user account be preserved, what U.S.C. statute authorizes this phone

call and obligates the ISP to preserve e-mail records?


A. Title 18, Section 1030


B. Title 18, Section 2703(d)


C. Title 18, Section Chapter 90


D. Title 18, Section 2703(f) - ✔✔D. Title 18, Section 2703(f)


Item 2If you come across a sheepdip machine at your client site, what

would you infer? - ✔✔C. A sheepdip computer is used only for virus-

checking.



1
100% Pass Guarantee Katelyn Whitman, All Rights

,In a computer forensics investigation, what describes the route that

evidence takes from the time you find it until the case is closed or goes to

court?


A. rules of evidence


B. law of probability


C. chain of custody


D. policy of separation - ✔✔C. chain of custody


How many characters long is the fixed-length MD5 algorithm checksum of

a critical system file?


A. 128


B. 64


C. 32


D. 16 - ✔✔C. 32


You are working on a thesis for your doctorate degree in Computer

Science. Your thesis is based on HTML, DHTML, and other web-based




2
100% Pass Guarantee Katelyn Whitman, All Rights

,languages and how they have evolved over the years.You navigate to

archive. org and view the HTML code of news.com. You then navigate to

the current news.com website and copy over the source code. While

searching through the code, you come across something abnormal: What

have you found?


A. Web bug


B. CGI code


C. Trojan.downloader


D. Blind bug - ✔✔A. Web bug


You are using DriveSpy, a forensic tool and want to copy 150 sectors where

the starting sector is 1709 on the primary hard drive. Which of the

following formats correctly specifies these sectors?


A. 0:1000, 150


B. 0:1709, 150


C. 1:1709, 150


D. 0:1709-1858 - ✔✔B. 0:1709, 150


3
100% Pass Guarantee Katelyn Whitman, All Rights

, A honey pot deployed with the IP 172.16.1.108 was compromised by an

attacker. Given below is an excerpt from a Snort binary capture of the

attack. Decipher the activity carried out by the attacker by studying the log.

Please note that you are required to infer only what is explicit in the

excerpt.(Note: The student is being tested on concepts learnt during

passive OS fingerprinting, basic TCP/IP connection concepts and the

ability to read packet signatures from a sniff dump.)03/15-20:21:24.107053

211.185.125.124:3500 -> 172.16.1.108:111TCP TTL:43 TOS:0x0 ID:29726

IpLen:20 DgmLen:52 DF***A**** Seq: 0x9B6338C5 Ack: 0x5820ADD0 Win:

0x7D78 TcpLen: 32TCP Options (3) => NOP NOP TS: 23678634 2878772

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=

+=+=+=+=+=+=+=+=03/15-20:21:24.452051 211.185.125.124:789 ->

172.16.1.103:111UDP TTL:43 TOS:0x0 ID:29733 IpLen:20 DgmLen:84Len: 64

-01 0A 8A 0A 00 00 00 00 00 00 00 02 00 01 - ✔✔A. The attacker has

conducted a network sweep on port 111


The newer Macintosh Operating System is based on:


A. OS/2



4
100% Pass Guarantee Katelyn Whitman, All Rights

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller KatelynWhitman. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $13.49. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

66060 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 15 years now

Start selling
$13.49
  • (0)
Add to cart
Added