Answers | Verified | Latest Update
What term describes data about information, such as disk partition structures and
files tables? - ANSWER-Metadata
Data stored as written matter, on paper or electronic files -
ANSWER-Documentary Evidence
Most common protocol used at OSI layer 3 - ANSWER-IP
ACT passed to improve the security and privacy of sensitive information in
federal computer systems. Law establishes minimum acceptable security
practices, creation of computer security plans, and training of system users and
owners of facilities that house sensitive information. - ANSWER-Computer
Security Act of 1987
The standard holding that only methods and tools widely accepted in scientific
community can be used in court. - ANSWER-Dauber Standard
Considered to be the use of analytical and investigative techniques to
identify,collect,, examine, and preserve evidence or information that is
magnetically stored or encoded. - ANSWER-Computer forensics
Information that has been processed and assembled to be relevant to an
investigation, and that supports a specific finding or determination. -
ANSWER-Digital Evidence
Establishes a standard of information-handling practices that govern the
collection, maintenance, use, and dissemination of information about individuals
that is maintained in the systems of record by U.S. federal agencies -
ANSWER-Federal Privacy Act of 1974
,The process of examining malicious computer code is known as? -
ANSWER-Software Forensics
What should you note all cable connections for a computer you want to seize as
evidence: - ANSWER-In case other devices were connected
What layer of the OSI Model does physical computer ports operate? -
ANSWER-Layer 1
First File system created specifically for Linux - ANSWER-Extended File System
Daubert Standard - ANSWER-1. A test of scientific acceptability applicable to the
gathering of evidence in criminal cases.
2. Only tools or techniques that have been accepted by the scientific community
are admissible at trial.
Federal wiretap law for traditional wired telephony. Expanded to include wireless,
voice over packet , and other forms of electronic communications. -
ANSWER-Communications Assistance to Law Enforcement Act of 1994
A breach of a file server that resulted in several stolen files, which federal law
applies? - ANSWER-18 U.S.C. C 1030, Fraud and Related Activity in Connection
with Computers
The process of examining malicious computer code is known as? -
ANSWER-Software Forensics
The intentional copy and use of the intellectual property? - ANSWER-Data Piracy
Type of Spyware products? - ANSWER-PowerSpy; Verity; ICU; and Work Time
A good fictitious email get what percent response rate? - ANSWER-1-3%
Define rules of evidence - ANSWER-Rules that govern whether, when, how, and
why proof of a legal case can be placed before a judge or jury
,Tools that enable an investigator to reconstruct file fragments if files have been
deleted or overwritten. Forensic specialist must therefore have tools that allow
manipulation and evaluation of bit-level information. - ANSWER-Bit-level
The unused space between the logical end of the file and the physical end of the
file. - ANSWER-File Slack or Slack Space
Definition of Digital Evidence - ANSWER-Information that has been processed
and assembled so that it is relevant to an investigation and supports a specific
finding or determination
Linux Live CD that you use to boot a system and then use the tools. Offers a
wide number of general security and hacking tools. - ANSWER-BackTrack
Forensics - ANSWER-the use of science and technology to investigate and
establish facts in criminal or civil courts of law."
Analysis Plan - ANSWER-What should be created before a forensic examination
can begin. Guides work in the analysis process.
Bit-level information - ANSWER-information at the level of actual 1s and 0s
stored in memory or on the storage device
You should only touch the actual original evidence any more than you have to,
why? - ANSWER-There is some chance of altering it
What are the three basic task for handling evidence - ANSWER-1. Find Evidence
2. Preserve Evidence
3. Prepare Evidence
Expert Report - ANSWER-Formal document that details the expert's findings
How many copies of a suspect drive should make to work with? - ANSWER-Two
Copies Each (using different imaging)
What is the four Stage framework for the Scientific Working Group on Digital
Evidence (SWGDE) - ANSWER-1. Collect
, 2. Preserve
3. Examine
4. Transfer
Forensic certification is open to both the public and private sectors and is specific
to the use and mastery of FTK. Requirements for taking the exam include
completing boot camp and windows forensic courses. - ANSWER-AccessData
Certified Examiner
Sets the standards for digital evidence processing, analysis, and diagnostics -
ANSWER-The DoD Cyber Crime Center (DC3)
Involves the authentication of evidence-based on scientific or technical
knowledge relevant to cases - ANSWER-Expert Testimony
Data that changes rapidly and may be lost when the machine that holds it is
powered down - ANSWER-Volatile Data
Physical Analysis - ANSWER-offline analysis conducted on an evidence disk or
forensic duplicate after booting from a CD or another system
Logical analysis - ANSWER-Analysis involving using the native operating
system, on the evidence disk or a forensic duplicate, to peruse the data
Unallocated Space - ANSWER-Free space, or the area of a hard drive that has
never been allocated for file storage.
Sweepers or scrubbers - ANSWER-A kind of software that cleans unallocated
space also called a scrubber
Basic Input/Output System (BIOS) - ANSWER-The software built into the ROM
chip that is the first code run by a computer when it is powered on. Its primary
function is to identify and test the devices attached to the computer that are used
to input and output information, such as the keyboard, monitor, hard drives, serial
communications, and so on. Some newer computers, such as Apple Macintosh
computers, use EFI instead of BIOS.