COMPUTER FORENSICS AND
INVESTIGATIONS COMPREHENSIVE EXAM
SCRIPT VERIFIED QUESTIONS AND
SOLUTIONS GRADED APLUS
●● Digital Forensics
Answer: In October 2012, an ISO standard for digital forensics was
ratified - ISO 27037 Information technology - Security techniques
●● The Federal Rules of Evidence (FRE)
Answer: was created to ensure consistency in federal proceedings
Signed into law in 1973
Many states' rules map to the FRE
●● FBI Computer Analysis and Response Team (CART
Answer: was formed in 1984 to handle cases involving digital evidence
By late 1990s, CART teamed up with Department of Defense Computer
Forensics Laboratory (DCFL)
●● The Fourth Amendment
Answer: to the U.S. Constitution protects everyone's right to be secure
from search and seizure
,Separate search warrants might not be necessary for digital evidence
Every U.S. jurisdiction has case law related to the admissibility of
evidence recovered from computers and other digital devices
●● Investigating digital devices includes:
Answer: Collecting data securely
Examining suspect data to determine details such as origin and content
Presenting digital information to courts
Applying laws to digital device practices
●● Digital forensics is different from data recovery
Answer: Which involves retrieving information that was deleted by
mistake or lost during a power surge or server crash
●● Forensics investigators
Answer: often work as part of a team, known as the investigations triad
●● Vulnerability/threat assessment and risk management
Answer: Tests and verifies the integrity of stand-along workstations and
network servers
●● Network intrusion detection and incident response
, Answer: Detects intruder attacks by using automated tools and
monitoring network firewall logs
●● Digital Investigations
Answer: Manages investigations and conducts forensics analysis of
systems suspected of containing evidence
●● A Brief History of Digital Forensics
Answer: By the early 1990s, the International Association of Computer
Investigative Specialists (IACIS) introduced training on software for
digital forensics
IRS created search-warrant programs
ASR Data created Expert Witness for Macintosh
ILook is currently maintained by the IRS Criminal Investigation
Division
AccessData Forensic Toolkit (FTK) is a popular commercial product
●● Understanding Case Law
Answer: Existing laws can't keep up with the rate of technological
change
●● When statutes don't exist, case law is used
Answer: Allows legal counsel to apply previous similar cases to current
one in an effort to address ambiguity in laws
INVESTIGATIONS COMPREHENSIVE EXAM
SCRIPT VERIFIED QUESTIONS AND
SOLUTIONS GRADED APLUS
●● Digital Forensics
Answer: In October 2012, an ISO standard for digital forensics was
ratified - ISO 27037 Information technology - Security techniques
●● The Federal Rules of Evidence (FRE)
Answer: was created to ensure consistency in federal proceedings
Signed into law in 1973
Many states' rules map to the FRE
●● FBI Computer Analysis and Response Team (CART
Answer: was formed in 1984 to handle cases involving digital evidence
By late 1990s, CART teamed up with Department of Defense Computer
Forensics Laboratory (DCFL)
●● The Fourth Amendment
Answer: to the U.S. Constitution protects everyone's right to be secure
from search and seizure
,Separate search warrants might not be necessary for digital evidence
Every U.S. jurisdiction has case law related to the admissibility of
evidence recovered from computers and other digital devices
●● Investigating digital devices includes:
Answer: Collecting data securely
Examining suspect data to determine details such as origin and content
Presenting digital information to courts
Applying laws to digital device practices
●● Digital forensics is different from data recovery
Answer: Which involves retrieving information that was deleted by
mistake or lost during a power surge or server crash
●● Forensics investigators
Answer: often work as part of a team, known as the investigations triad
●● Vulnerability/threat assessment and risk management
Answer: Tests and verifies the integrity of stand-along workstations and
network servers
●● Network intrusion detection and incident response
, Answer: Detects intruder attacks by using automated tools and
monitoring network firewall logs
●● Digital Investigations
Answer: Manages investigations and conducts forensics analysis of
systems suspected of containing evidence
●● A Brief History of Digital Forensics
Answer: By the early 1990s, the International Association of Computer
Investigative Specialists (IACIS) introduced training on software for
digital forensics
IRS created search-warrant programs
ASR Data created Expert Witness for Macintosh
ILook is currently maintained by the IRS Criminal Investigation
Division
AccessData Forensic Toolkit (FTK) is a popular commercial product
●● Understanding Case Law
Answer: Existing laws can't keep up with the rate of technological
change
●● When statutes don't exist, case law is used
Answer: Allows legal counsel to apply previous similar cases to current
one in an effort to address ambiguity in laws