Free CPSA (CPIA) Questions and Answers — Questions and Answers
Question 1: When gathering evidence, you should start with the most volatile and work your way down.
- RFC 3227 - 1 (Correct answer)
- Acpo guidelines - principle 2
- Acpo guidelines - principle 3
- Rfc 3227 - 9
Correct answer: RFC 3227 - 1
RFC 3227, titled 'Guidelines for Evidence Collection and Archiving,' provides recommendations for digital forensics. Principle 1 of this RFC specifically states that when gathering evidence, one should start with the most volatile data and proceed to the least volatile. This ensures that transient information, which can be easily lost (like RAM contents or network connections), is captured before it disappears.
Question 2: Data stored on a computer or other storage medium that may later be cited in court should not be altered by law enforcement authorities or their agents.
- Acpo Guidelines - Principle 2
- Acpo Guidelines - Principle 4
- ACPO Guidelines - Principle 1 (Correct answer)
- Acpo Guidelines - Principle 3
Correct answer: ACPO Guidelines - Principle 1
The ACPO (Association of Chief Police Officers) Guidelines for Computer-Based Electronic Evidence are fundamental principles in digital forensics. Principle 1 states that 'No action taken by law enforcement agencies or their agents should change data held on a computer or storage media which may subsequently be relied upon in court.' This principle emphasizes the importance of preserving the integrity of digital evidence to ensure its admissibility and reliability in legal proceedings.
Question 3: The steps performed from the moment an event is reported all the way up to its full rehabilitation, as well as post-incident evaluations.
- Definition of Governance
- Goals of Incident Response
- What is Incident Response? (Correct answer)
- Rootkits 2 - Kernal Mode 2
Correct answer: What is Incident Response?
Incident response encompasses the structured approach an organization takes to manage and recover from a security breach or cyberattack. It involves a series of steps, from the initial detection and reporting of an event, through containment, eradication, and recovery, all the way to post-incident analysis and lessons learned, aiming to minimize damage and restore normal operations.
Question 4: A computer breach is a circumstance that affects a computer's C.I.A., either intentionally or unintentionally.
- ACPO Guidelines - Principle 2 in Practise
- USB Drives - Identifiable Electronic Numbers
- ACPO Guidelines - Principle 4 in Practise
- How Do We Define A Computer Breach or Intrusion? (Correct answer)
Correct answer: How Do We Define A Computer Breach or Intrusion?
A computer breach or intrusion is generally defined as any event that compromises the confidentiality, integrity, or availability (CIA triad) of a computer system or its data, whether intentionally or unintentionally. This can range from unauthorized access to data, data modification, or denial of service, impacting the security posture of an organization.
Question 5: The case officer, who is in charge of the inquiry, is ultimately responsible for making sure that the law and these principles are followed.
- Acpo Guidelines - Principle 2
- Acpo Guidelines - Principle 3
- Acpo Guidelines - Principle 8
- ACPO Guidelines - Principle 4 (Correct answer)
Correct answer: ACPO Guidelines - Principle 4
ACPO Guidelines Principle 4 states that 'The person in charge of the investigation (the case officer) has overall responsibility for ensuring that the law and these principles are adhered to.' This principle assigns ultimate accountability to the case officer for the proper conduct of a digital forensics investigation, ensuring compliance with legal requirements and forensic best practices.
Question 6: Fairly and lawfully processed, Processed for a limited purpose, Adequate, relevant and not excessive, and Secure. <br> Answer: Data Protection Act 2018 Principles
- True (Correct answer)
- False
Correct answer: True
The Data Protection Act 2018 (DPA 2018), which supplements the GDPR in the UK, outlines several key principles for processing personal data. These include requirements for data to be processed fairly, lawfully, and transparently, collected for specified and legitimate purposes, adequate, relevant, and limited to what is necessary, accurate, kept for no longer than necessary, and processed in a manner that ensures appropriate security. The listed characteristics align with these principles.
Question 7: Definition of Governance <br> Answer: The actions taken starting from when an incident is raised and following it through to complete remediation as well as the post incident assessments.
- True
- False (Correct answer)
Correct answer: False
The provided definition describes 'Incident Response,' not 'Governance.' Governance, in an organizational context, refers to the system by which an organization is directed and controlled, encompassing policies, processes, and structures for decision-making and accountability. Incident response is a process that falls under the broader umbrella of IT or security governance.
When gathering evidence, you should start with the most volatile and work your way down.