WGU D431 DIGITAL FORENSICS COMPREHENSIVE
QUESTIONS AND ANSWERS SURE A+
✔✔Partition Types - ✔✔determines how the partition is organized on the drive.
✔✔GUID Partition Table - ✔✔- is used primarily with computers that have an Intel-
based processor
✔✔Oxygen Forensics - ✔✔- This is a full forensic tool capable of imaging and
examining iPhones and Android phones.
-It provides a number of user-friendly tools for extracting specific data such as contacts,
social media data, etc
✔✔Cellebrite - ✔✔- This is probably the most widely known phone forensics tool.
-It is used heavily by federal law enforcement. It is a very robust and effective tool.
-The only downside is that It is the most expensive phone forensics tool on the market
✔✔MobileEdit - ✔✔- This is a very easy-to-use tool that can aid a forensic examiner in
extracting data from cell phones
✔✔Data Doctor - ✔✔- This product recovers all Inbox and Outbox data and all contacts
data, and has an easy-to-use interface. Most important, it has a free trial version, but
there is a cost for the full version
✔✔Forensic SIM Cloner - ✔✔This tool is used to clone SIM cards, allowing you to
perform forensic analysis of the SIM card.
✔✔Pwnage - ✔✔This utility allows you to unlock a locked iPod Touch
✔✔Recover My iPod - ✔✔This utility allows you to recover files deleted from an iPod
✔✔APowerSoft - ✔✔- This is a general deleted file utility for iPhone and related devices
✔✔iMyPhone - ✔✔- makes a number of utilities for data recovery for iPhone and related
devices
✔✔iPhone Analyzer - ✔✔- This is a free Java program used to analyze iPhone backups
✔✔ Disk Forensics - ✔✔- the process of acquiring and analyzing information stored on
a physical storage media, such as computer hard drives , smartphones, GPS systems
and removable media
, - includes both the recovery of hidden and deleted information and the process of
identifying who created a file or message
✔✔Email Forensics - ✔✔- the study of the source and content of email as evidence
- includes the process of identifying the sender, recipient, date, time and origination or
unauthorized activities
✔✔Network Forensics - ✔✔- the process of examining network traffic, including
transaction logs and real time monitoring using sniffers and tracing
✔✔Internet forensics - ✔✔- the process of piecing together where and when a user has
been on the Internet
- ex you can use to determine whether inappropriate Internet content access and
downloading were accidental
✔✔Software forensics ( malware forensics) - ✔✔- the process of examining malicious
computer code
✔✔Live system forensics - ✔✔- the process of searching memory in real time , typically
for working with compromised hosts or to identify system abuse
✔✔Cell-phone forensics - ✔✔- the process of searching the contents of cell phones
✔✔Daubert Standard - ✔✔- standard used by a trial judge to make a preliminary
assessment of whether an expert's scientific testimony is based on reasoning or
methodology that is scientifically valid and can properly be applied to the facts at issue
✔✔The federal privacy act of 1974 - ✔✔- establishes a code of information handling
practices that governs the collection, maintenance,use, and dissemination of
information about individuals that is maintained in systems of records by us federal
agencies
✔✔System of record - ✔✔- a group of records under the control of an agency from
which information is retrieved by the name of the individual or by some identifier
assigned to the individual
✔✔The privacy protection act of 1980 - ✔✔- protects journalists from being required to
turn over to law enforcement any work product and documentary materials, including
sources, before it is disseminated to the public
QUESTIONS AND ANSWERS SURE A+
✔✔Partition Types - ✔✔determines how the partition is organized on the drive.
✔✔GUID Partition Table - ✔✔- is used primarily with computers that have an Intel-
based processor
✔✔Oxygen Forensics - ✔✔- This is a full forensic tool capable of imaging and
examining iPhones and Android phones.
-It provides a number of user-friendly tools for extracting specific data such as contacts,
social media data, etc
✔✔Cellebrite - ✔✔- This is probably the most widely known phone forensics tool.
-It is used heavily by federal law enforcement. It is a very robust and effective tool.
-The only downside is that It is the most expensive phone forensics tool on the market
✔✔MobileEdit - ✔✔- This is a very easy-to-use tool that can aid a forensic examiner in
extracting data from cell phones
✔✔Data Doctor - ✔✔- This product recovers all Inbox and Outbox data and all contacts
data, and has an easy-to-use interface. Most important, it has a free trial version, but
there is a cost for the full version
✔✔Forensic SIM Cloner - ✔✔This tool is used to clone SIM cards, allowing you to
perform forensic analysis of the SIM card.
✔✔Pwnage - ✔✔This utility allows you to unlock a locked iPod Touch
✔✔Recover My iPod - ✔✔This utility allows you to recover files deleted from an iPod
✔✔APowerSoft - ✔✔- This is a general deleted file utility for iPhone and related devices
✔✔iMyPhone - ✔✔- makes a number of utilities for data recovery for iPhone and related
devices
✔✔iPhone Analyzer - ✔✔- This is a free Java program used to analyze iPhone backups
✔✔ Disk Forensics - ✔✔- the process of acquiring and analyzing information stored on
a physical storage media, such as computer hard drives , smartphones, GPS systems
and removable media
, - includes both the recovery of hidden and deleted information and the process of
identifying who created a file or message
✔✔Email Forensics - ✔✔- the study of the source and content of email as evidence
- includes the process of identifying the sender, recipient, date, time and origination or
unauthorized activities
✔✔Network Forensics - ✔✔- the process of examining network traffic, including
transaction logs and real time monitoring using sniffers and tracing
✔✔Internet forensics - ✔✔- the process of piecing together where and when a user has
been on the Internet
- ex you can use to determine whether inappropriate Internet content access and
downloading were accidental
✔✔Software forensics ( malware forensics) - ✔✔- the process of examining malicious
computer code
✔✔Live system forensics - ✔✔- the process of searching memory in real time , typically
for working with compromised hosts or to identify system abuse
✔✔Cell-phone forensics - ✔✔- the process of searching the contents of cell phones
✔✔Daubert Standard - ✔✔- standard used by a trial judge to make a preliminary
assessment of whether an expert's scientific testimony is based on reasoning or
methodology that is scientifically valid and can properly be applied to the facts at issue
✔✔The federal privacy act of 1974 - ✔✔- establishes a code of information handling
practices that governs the collection, maintenance,use, and dissemination of
information about individuals that is maintained in systems of records by us federal
agencies
✔✔System of record - ✔✔- a group of records under the control of an agency from
which information is retrieved by the name of the individual or by some identifier
assigned to the individual
✔✔The privacy protection act of 1980 - ✔✔- protects journalists from being required to
turn over to law enforcement any work product and documentary materials, including
sources, before it is disseminated to the public