Order ready-to-submit essays. No Plagiarism Guarantee!
Note: All our papers are written from scratch by human writers to ensure authenticity and originality.
CIS 359 Final Exam Set 2
Check your essay before you submit. See exactly what your professor sees.
See your AI and plagiarism results before your instructor does.Get the exact same report your professor uses. Trusted by 50,000+ students worldwide.
• Question 1
A continuously changing process presents challenges in acquisition, as there is not a fixed state that can be collected, hashed, and so forth. This has given rise to the concept of __ forensics which captures a point-in-time picture of a process.
• Question 2
__ is used both for intrusion analysis and as part of evidence collection and analysis.
• Question 3
In evidence handling, specifically designed __ are helpful because they are very difficult to remove without breaking.
• Question 4
A search is constitutional if it does not violate a person’s reasonable or legitimate____.
• Question 5
The forensic tool __ does extensive pre-processing of evidence items that recovers deleted files and extracts e-mail messages.
• Question 6
Most digital forensic teams have a prepacked field kit, also known as a(n) __.
• Question 7
The __ handles computer crimes that are categorized as felonies.
• Question 8
Forensic investigators use __ copying when making a forensic image of a device, which reads a sector (or block; 512 bytes on most devices) from the source drive and writes it to the target drive; this process continues until all sectors on the suspect drive have been copied.
• Question 9
Grounds for challenging the results of a digital investigation can come from possible __—that is, alleging that the relevant evidence came from somewhere else or was somehow tainted in the collection process.
• Question 10
The U.S. Department of Homeland Security’s Federal Emergency Management Association has developed a support Web site at __ that includes a suite of tools to guide the development of disaster recovery/business continuity plans.
• Question 11
Identifying measures, called __, that reduce the effects of system disruptions can reduce continuity life-cycle costs.
• Question 12
Two dominantly recognized professional institutions certifying business continuity professionals agree on the __ as the basis for certification.
• Question 13
Unless an organization has contracted for a __ or equivalent, office equipment such as desktop computers are not provided at BC alternate site.
• Question 14
__ planning represents the final response of the organization when faced with any interruption of its critical operations.
• Question 15
A BC subteam called the __ is responsible for establishing the core business functions needed to sustain critical business operations.
• Question 16
One activity that occurs during the clearing phase of a BC implementation is scheduling a move back to the primary site.
• Question 17
In the __ phase of the BC plan, the organization specifies what type of relocation services are desired and what type of data management strategies are deployed to support relocation.
• Question 18
__ occur over time and slowly deteriorate the organization’s capacity to withstand their effects.
• Question 19
Contingency strategies for __ should emphasize the need for absolutely reliable data backup and recovery procedures because they have less inherent redundancy than a distributed architecture.
• Question 20
__ may be caused by earthquakes, floods, storm winds, tornadoes, or mud flows.
• Question 21
__ disasters include acts of terrorism and acts of war.
• Question 22
Once the incident has been contained, and all signs of the incident removed, the __ phase begins.
• Question 23
A __ is a description of the disasters that may befall an organization, along with information on their probability of occurrence, a brief description of the organization’s actions to prepare for that disaster, and the best case, worst case, and most likely case outcomes of the disaster.
• Question 24
__ are highly probable when infected machines are brought back online or when other infected computers that may have been offline at the time of the attack are brought back up.
• Question 25
The part of a disaster recovery policy that identifies the organizational units and groups of employees to which the policy applies is called the __ section.
• Question 26
__ is the set of actions taken by an organization in response to an emergency situation in an effort to minimize injury or loss of life.
• Question 27
In contrast to emergency response that focuses on the immediate safety of those affected, __ addresses the services needed to get the organization and its stakeholders back to original levels of productivity or satisfaction.
• Question 28
__ is the movement of employees from one position to another so they can develop additional skills and abilities.
• Question 29
A(n) __ is the list of officials ranging from an individual’s immediate supervisor through the top executive of the organization.
• Question 30
A(n) __ is created to enable management to gain and maintain control of ongoing emergency situations, to provide oversight and control to designated first responders, and to marshal IR, DR, and DC plans and resources as needed.
• Question 31
Organizations typically respond to a crisis by focusing on technical issues and economic priorities, and overlook the steps needed to preserve the most critical assets of the organization: its people.
• Question 32
__ are those actions taken in order to manage the immediate physical, health, and environmental impacts resulting from an incident.
• Question 33
__ refers to those actions taken to meet the psychological and emotional needs of various stakeholders.
• Question 34
According to the 2010/2011 Computer Crime and Security Survey, __ is “the most commonly seen attack, with 67.1 percent of respondents reporting it.”
• Question 35
When an alert warns of new malicious code that targets software used by an organization, the first response should be to research the new virus to determine whether it is __.
• Question 36
In a “block” containment strategy, in which the attacker’s path into the environment is disrupted, you should use the most precise strategy possible, starting with __.
• Question 37
If a user receives a message whose tone and terminology seems intended to invoke a panic or sense of urgency, it may be a(n) __.
• Question 38
Many malware attacks are __ attacks, which involve more than one type of malware and/or more than one type of transmission method.
• Question 39
A __ is a small quantity of data kept by a Web site as a means of recording that a system has visited that Web site.
• Question 40
A(n) __ attack is a method of combining attacks with rootkits and back doors.
• Question 41
According to NIST, which of the following is an example of a UA attack?
• Question 42
Which of the following is the most suitable as a response strategy for malware outbreaks?
• Question 43
The __ team is responsible for working with suppliers and vendors to replace damaged or destroyed equipment or services, as determined by the other teams.
• Question 44
The __ team is responsible for the recovery of information and the reestablishment of operations in storage area networks or network attached storage.
• Question 45
The __ system is an information system with a telephony interface that can be used to automate the alert process.
• Question 46
__ is the inclusion of action steps to minimize the damage associated with the disaster on the operations of the organization.
• Question 47
The __ team is primarily responsible for data restoration and recovery.
• Question 48
The __ is the phase associated with implementing the initial reaction to a disaster; it is focused on controlling or stabilizing the situation, if that is possible.
• Question 49
The __ team is responsible for recovering and reestablishing operating systems (OSs).
• Question 50
During the __ phase, the organization begins the recovery of the most time-critical business functions – those necessary to reestablish business operations and prevent further economic and image loss to the organization.


