accurate answers
Backups Ans✓✓✓Are terrible in telling you what happened right now
but are good at detailing trends. Low volatility but can take a while to
grab the data
Chain of Custody (CoC) Ans✓✓✓A list of all people who came into
possession of an item of evidence against someone or something. Vital
to show good integrity of data
CoC Process: Date/time collected Ans✓✓✓Very important to detail
when it was collected
CoC Process: Define Evidence Ans✓✓✓What are we actually
gathering - what does it look like/how does it form? Video, image, file,
w/e
CoC Process: Document Collection Method Ans✓✓✓How did you
collect the data and is there a risk of it being changed during collection?
This can skew investigation results
CoC Process: Function of person handling evidence Ans✓✓✓Who are
they and why are they relevant to the problem/evidence/investigation
, CoC Process: Locations of the evidence Ans✓✓✓Evidence will move
over time. DO NOT LOSE IT. DOCUMENT EVERYTHING ABOUT
IT
CoC Process: Person(s) handling the evidence Ans✓✓✓Need to know
who exactly handled AND collected the evidence and how to contact
them
Cyber Incident Response Team (CIRT) Ans✓✓✓Defined by the US
Government as the IT security professionals who act first to implement
an incident response plan in the event of a problem.
Can include the IT department on top of the IT security team as well as
HR in case a person is involved with the issue as well as legal and public
relations
Data on the disc Ans✓✓✓Optical, flash drives - this data will disappear
on shutdown. Cache files, temp files, swap files
Digital Forensics Ans✓✓✓The discovery, collection, and analysis of
evidence found on computers and networks
Document Incident types Ans✓✓✓What is the incident? Physical
access, Malware, Phishing, Social engineering, data access?