exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 254 discussion

Actual exam question from Cisco's 200-201
Question #: 254
Topic #: 1
[All 200-201 Questions]

What are two differences between tampered disk images and untampered disk images? (Choose two.)

  • A. The image is tampered if the stored hash and the computed hash are identical.
  • B. Tampered images are used as an element for the root cause analysis report.
  • C. Untampered images can be used as law enforcement evidence.
  • D. Tampered images are used in a security Investigation process.
  • E. The image is untampered if the existing stored hash matches the computed one.
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaliDong
Highly Voted 1 year, 7 months ago
Selected Answer: CE
C and E should be the correct answers.
upvoted 6 times
...
SecurityGuy
Most Recent 9 months, 2 weeks ago
Selected Answer: CE
Same question with Q106. Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide by Omar Santos P570 - You do not use Tampered images in an investigation. They would be useless in Court. We preserve the evidence. - Evidence in cybersecurity investigations that go to court is used to prove (or disprove) facts that are in dispute, as well as to prove the credibility of disputed facts (in particular, circumstantial evidence or indirect evidence). - Digital forensics evidence provides implications and extrapolations that may assist in proving some key fact of the case. - Such evidence helps legal teams and the court develop reliable hypotheses or theories as to the committer of the crime (threat actor). - The reliability of the evidence is vital to supporting or refuting any hypothesis put forward, including the attribution of threat actors.
upvoted 2 times
...
cy_analyst
1 year, 7 months ago
Selected Answer: CE
CE are correct.
upvoted 4 times
...
Eng_ahmedyoussef
1 year, 8 months ago
Selected Answer: CE
C. Untampered images can be used as law enforcement evidence. E. The image is untampered if the existing stored hash matches the computed one.
upvoted 3 times
...
moali012
1 year, 8 months ago
Selected Answer: CE
I see the correct answer is C and E, because the tampered evidence should not be used in investigations
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...