試験科目:Logical Operations CyberSec First Responder
問題と解答:全100問 CFR-210 試験資料

>> CFR-210 試験資料


NO.1 A suspicious laptop is found in a datacenter. The laptop is on and processing data, although
there is no application open on the screen.
Which of the following BEST describes a Windows tool and technique that an investigator should use
to analyze the laptop's RAM for working applications?
A. Task manager and Application analysis
B. Volatility and Memory analysis
C. Net start and Network analysis
D. Regedit and Registry analysis
Answer: D


NO.2 Which of the following are legally compliant forensics applications that will detect ADS or a file
with an incorrect file extension? (Choose two.)
A. dd
C. Procmon
D. EnCase
E. Regedit
Answer: A,E


NO.3 Which of the following enables security personnel to have the BEST security incident recovery
A. Disaster recovery plan
B. Cyber incident response plan
C. Crisis communication plan
D. Occupant emergency plan
Answer: B


NO.4 A DMZ web server has been compromised. During the log review, the incident responder wants
to parse all common internal Class A addresses from the log.
Which of the following commands should the responder use to accomplish this?
A. grep -x"(192.168.[0.9]+[0-9])" bin/apache2/access.log I output.txt
B. grep -v"(10.[0-9]+.[0-9]+.[0-9]+)" /var/log/apache2/access.log > output.txt
C. grep -x"(10.[0-9]+.[0-9]+.[0-9]+)" etc/rc.d/apache2/access.log I output.txt
D. grep -v"(192.168.[0.9]+[0-9]+)" /var/log/apache2/access.log > output.txt
Answer: B

