Ch. 6 Current Digital Forensics Tools Exam |
Questions with 100% Correct Answers | Verified |
Latest Update 2026
Save
Terms in this set (30)
1. Forensic software tools are CL and GUI
grouped into ____________ and
_______________ applications.
2. According to ISO standard 27037, A& B
which of the following is an
important factor in data
acquisition? (Choose all that apply.)
a. The DEFR's competency
b. The DEFR's skills in using the
command line
c. Use of validated tools
d. Conditions at the acquisition
setting
3. One reason to choose a logical True
acquisition is an encrypted drive.
True or False?
, 4. Hashing, filtering, and file header Validation and verification
analysis make up which function of
digital forensics tools?
a. Validation and verification
b. Acquisition
c. Extraction
d. Reconstruction
5. Hardware acquisition tools most are used only for acquisition
typically have built-in software for
data analysis. True or False?
6. The reconstruction function is Re-create a suspect drive to show what happened.
needed for which of the following
purposes? (Choose all
that apply.)
a. Re-create a suspect drive to show
what happened.
b. Create a copy of a drive for other
investigators.
c. Recover file headers.
d. Re-create a drive compromised by
malware.
7. List three subfunctions of the data viewing, keyword searching, decompressing,
extraction function. carving, decrypting, and bookmarking.
8. Data can't be written to disk with a False
command-line tool. True or False?
Questions with 100% Correct Answers | Verified |
Latest Update 2026
Save
Terms in this set (30)
1. Forensic software tools are CL and GUI
grouped into ____________ and
_______________ applications.
2. According to ISO standard 27037, A& B
which of the following is an
important factor in data
acquisition? (Choose all that apply.)
a. The DEFR's competency
b. The DEFR's skills in using the
command line
c. Use of validated tools
d. Conditions at the acquisition
setting
3. One reason to choose a logical True
acquisition is an encrypted drive.
True or False?
, 4. Hashing, filtering, and file header Validation and verification
analysis make up which function of
digital forensics tools?
a. Validation and verification
b. Acquisition
c. Extraction
d. Reconstruction
5. Hardware acquisition tools most are used only for acquisition
typically have built-in software for
data analysis. True or False?
6. The reconstruction function is Re-create a suspect drive to show what happened.
needed for which of the following
purposes? (Choose all
that apply.)
a. Re-create a suspect drive to show
what happened.
b. Create a copy of a drive for other
investigators.
c. Recover file headers.
d. Re-create a drive compromised by
malware.
7. List three subfunctions of the data viewing, keyword searching, decompressing,
extraction function. carving, decrypting, and bookmarking.
8. Data can't be written to disk with a False
command-line tool. True or False?