Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

Digital Forensics EXAM 1 Questions With Detailed Correct Answers

Document preview thumbnail
Preview 2 out of 14 pages

relating to the use of scientific knowledge or methods in solving crimes - correct answers Forensic A discipline that combines elements of law and computer science in order to collect and analyze computer data from a variety of computer systems, networks, storage devices, and other devices using digital communications as the source and flow of information in a way that is admissible as evidence in a court of law. - correct answers Digital Forensics True - correct answers Digital forensics includes computer forensics as well as forensics on all other digital devices capable of storing digital data *Network forensics *Mobile device forensics *Activity tracking device forensics, etc. - correct answers Forensic Tools DF investigation does not need to have deepest understanding on theoretic knowledge on CS but must have a familiarity with a wide range of subject matter. - correct answers True e.g., computer network intrusion, DDOS attack - correct answers As a target of the crime Cyber Stalking and bullying Identity theft Pirated computer software Forgery or falsification of documents Corporate fraud Terrorism and national security - correct answers As an instrument of the crime Everything that enters a crime scene does two things. It leaves part of itself behind, and it takes part of the scene with it. - correct answers Locard's Exchange Principle According to some studies, almost 95 percent of criminals leave evidence which could be investigated through computer forensic procedure. - correct answers True Physical evidence cannot be wrong or wholly absent. Only human failure to find it, study and understand it, can diminish its value - correct answers (Paul Kirk, 1953) Things you can carry to court and show - correct answers Real evidence To support or validate other evidence types - correct answers Testimonial evidence Files, log, e-mail - correct answers Documentary evidence To recreate or explain other evidence - correct answers Demonstrative evidence Chat log, photo/video, image editing software, internet/SNS activity, movie files, relevant file and directory names - correct answers Child Exploitation Financial and asset data, credit card data, emails - correct answers Computer Fraud Network user id and IP addresses, virus and spyware, system logs, etc. - correct answers Network intrusion and hacking How was the BTK killer caught - correct answers Name found in Floppy Disk Evidence presented came from where he/she claims - correct answers Authenticity was not altered in any way during examination, and there was no opportunity for it to have been replaced or altered in the interim - correct answers Integrity Evidence must have a bearing on the event being investigated. Information about unrelated crime cannot be used as an evidence for the case. - correct answers Relevance Should be no question about the truth of the investigator's conclusion. Use standardized/verified forensics tools and methods (see Daubert guideline). Investigator qualification - correct answers Reliability Different regulation applies to internal/civil/criminal investigations while criminal investigation is most restrictive in terms of legal requirements. - correct answers Legally obtained Judge can render the evidence admissible or inadmissible - correct answers True Evidence presented in court should be ______and the actual item investigated or examined. - correct answers original Federal Rules of Evidence consider a____________ to be "original" if it can be read by sight and if it accurately represents the stored data. - correct answers printout of computer data A proper _______ can be considered Best evidence if the original evidence has been returned to its owner. - correct answers forensic image established new criteria to determine the reliability, relevancy, and admissibility of scientific evidence - correct answers The Case of Daubert v. Merrill Dow Pharmaceuticals (1993) Has the procedure been published in Journals and generally accepted? Had the procedure been independently tested and what is the error rate? - correct answers Guidelines for entering technical evidence into U.S. Court: A critical function of investigation that continuously records log information of each and every action that is taken on or against a piece of evidence and of every movement that evidence makes from the moment an object is identified as having evidentiary value. **Critical for evidence admissibility. - correct answers Chain of Custody To prohibit unreasonable searches and seizures and requires warrants to be judicially sanctioned and supported by probable cause. - correct answers The Fourth Amendment To prevent the government from ever forcing a citizen to provide self-incriminating testimony. - correct answers The Fifth Amendment passwords for protected/encrypted data can be forcefully acquired with a warrant - correct answers False Clearly state what you are searching for. Clearly state the area in which you are authorized to search. Be signed by a judge. - correct answers Search Warrant The "plain view" doctrine says that an officer can seize evidence that is in plain view as long as: The officer is legally present at the site of the evidence. The officer can legally access the evidence. The officer has probable cause to believe that the evidence or contraband is related to a crime. A device can be seized in case there is owner's written consent which acknowledges future forensic examination by trained examiner - correct answers No Search Warrant is required if.. Conducted In case of violation of company policies and guidelines - correct answers Internal Investigations Conducted In case of IPR risk, company's network security breach, unauthorized use of company resource E.g., Intrusion, DoS attack, malicious code/comm, misuse, etc. - correct answers Civil Investigations Internal Civil Criminal - correct answers 3 types of forensic investigations not subject to the same "search and seizure" rules and Fourth Amendment issues often involve misuse or abuse of company assets, falsification of data, discrimination, harassment, and similar matters likely to involve litigation. - correct answers Corporate/private Investigation E.g., employees who violate the company's security policy - correct answers Corporate/private Investigation Digital Forensics Hardware Tools Can be used for _______ response and forensic _____ - correct answers incident, laboratory Forensics computers Write-blocking devices Imaging devices (disk duplicator) Data wiping devices Encryption hardware - correct answers Digital Forensics Hardware Tools Imaging devices - correct answers _____ is a discipline that collect and analyze data from computing devices to find court-admissible evidence. - correct answers Digital forensics Digital forensics requires knowledge on ____ and computer science as well as various forensic _____and software tools. - correct answers law, hardware ______must be authentic, reliable, relevant, integrity guaranteed, legally obtained to be admissible to a court. - correct answers Digital evidence Collection Examination Analysis Reporting - correct answers Forensic Investigation Process -(American Board of Information Security and Computer Forensics) Identify, isolate, label, record, and collect the data and physical evidence related to the incident being investigated, while establishing and maintaining integrity of the evidence through chain-of-custody. - correct answers Collection (Acquisition) Identify and extract the relevant information from the collected data, using appropriate forensic tools and techniques, while continuing to maintain integrity of the evidence. - correct answers Examination Analyze the results of the examination to generate useful answers to the questions presented in the previous phases. - correct answers Analysis The case is typically "solved" in this phase. - correct answers Analysis Phase Reporting the results of the analysis, including: Findings relevant to the case Actions that were performed Actions left to be performed Recommended improvements to procedures and tools - correct answers Reporting -Preparation: prepare equipment and tools, -Collection: Search physical location for possible digital evidence and acquire (e.g., collect or copy digital media) -Examination: review the media for evidence (initial screening) -Analysis: review the results for their value in the case -Reporting: document results of investigation - correct answers DOJ guidelines - late 90's 1) Identification/Assessment 2) Collection/acquisition 3) Preservation 4) Examination 5) Analysis 6) Reporting - correct answers Digital Investigation in 6 Steps - by Casey (2004) Secure entrance/exit Prevent changes - Phase Goals (Physical) - correct answers Preservation (Physical) Prevent changes (network isolation, collecting volatile data, copy entire digital environment -Phase Goals (Digital) - correct answers Preservation (Digital) Walking through scene Identify evidence - Phase Goals (Physical) - correct answers Survey (Physical) Identify obvious evidence (in lab) -Phase Goals (Digital) - correct answers Survey(Digital) Photograph, sketches, evidence/scene maps - Phase Goals (Physical) - correct answers documentation (Physical) Photo & description of digital device -Phase Goals (Digital) - correct answers documentation (Digital) In-depth search - Phase Goals (Physical) - correct answers Search & Collection (Physical) Analysis of system for nonobvious evidence -Phase Goals (Digital) - correct answers Search & Collection (Digital) Develop theories - Phase Goals (Physical) - correct answers reconstruction (Physical) Similar to physical -Phase Goals (Digital) - correct answers reconstruction (Digital) Response to a computer crime, security policy violation, or similar event Secure, preserve and document digital evidence Happens BEFORE the forensic analysis begins. Incident responder is not necessarily the forensic specialist who will conduct the analysis of the digital evidence - correct answers Incident Response Large company incident responder might be a technician-level employee in security or information technology Small company network administrator or security officer might also be the incident responder - correct answers Incident Response - Corporate a sworn law enforcement officer or "crime lab" technician can be ______ - correct answers an Incident Responder Safety first. Integrity second. (computer, data, network) Then secure evidence. - correct answers Securing the Scene (by first responder or DFI (DIGITAL FORENSICS INVESTIGATOR) If computer is on, leave it on. If computer is off, leave it off. No technical assist from anyone unauthorized should be allowed. Avoid compromising physical evidence (fingerprint, blood, DNA, etc.) on computer devices (mouse, keyboard, etc.) Protect yourself from biohazards - correct answers Guideline for First Responder Immediately halts processing but destroys data in memory and can corrupt files Data in memory could be collected using "cold boot" attack or DMA attack. - correct answers Pull the plug Writes entries into the system activity logs (change of the state of the evidence) - correct answers Shut down This method uses two separate computer systems ‐‐ the suspect and a specialized forensics imaging system. - correct answers System‐to‐System Disk Imaging Also known as System BIOS, ROM BIOS or PC BIOS - correct answers Basic Input Output System (BIOS) RAM with battery - correct answers Complementary Metal Oxide Silicon (CMOS) Checking the BIOS chip and then tests CMOS RAM Checking video card, hard drives, floppy drives, ports, keyboard and mouse, etc. If functioning properly, successful CPU initialization - correct answers Power On Self Test (POST) Sun SPARC and Motorola PowerPC (i.e., Apple computers) systems use_______ordering. - correct answers Big Endian IA32-based systems (i.e., Intel Pentium) and their 64-bit counterparts use the ______ ordering. - correct answers little-endian assigns a numerical value to the characters in American English. - correct answers ASCII "American Standard Code for Information Interchange" - correct answers ASCIII stands for the Allows for Characters besides English, ex Japanese - correct answers Unicode ASCII works if you use ______ only limited for the rest of the world because their native symbols cannot be represented. - correct answers American English UTF (Unicode Transformation Formats)- 32 UTF-16 UTF- - correct answers Three ways of storing a Unicode character (Integrated Disk Electronics) or PATA IDE means a hard disk has a built-in logic board IDE disk uses ATA interface 40 or 44 pin connectors - correct answers ATA/IDE Better cable and speed, no jumpers direct connect to controller (no chaining of devices) - correct answers SATA (serial ATA) (Small Computer Systems Interface) More costly, used mainly for servers Various connector types (difficult to carry all) - correct answers SCSI The smallest addressable unit of storage - correct answers Sector A group of sector Allocation unit of data in file systems - correct answers Cluster Cylinder address (C), Head number (H), Sector address (S) Based on Physical address Obsolete, older computers still use it. - correct answers CHS LBA address 0 = CHS address 0,0,1 LBA address 1 = CHS address 0,0,2 CHS 0,1,1 = sector 1 of the second head in the same cylinder - correct answers LBA (logical Block address) a special area of the disk that can be used to save data a casual observer (including OS) might not see it. - correct answers Host Protected Area (HPA) HPA is created at the end of _____ - correct answers hard disk is a collection of addressable sectors that an Operating System (OS) or application can use for data storage. The sectors in a volume need not be consecutive on a physical storage device - correct answers A volume is a collection of consecutive sectors in a volume. - correct answers Partition The purpose of a partition system is to organize the layout of a volume - correct answers True is in the first 512-byte sector of a disk - correct answers MBR (MASTER BOOT RECORD) MBR includes partition table which has _____entries. (up to ____ partitions) - correct answers Four,4 is a partition whose entry is in the MBR and the partition contains a file system or other structured data. - correct answers primary file system partition is a partition whose entry is in the MBR, and the partition contains additional partitions. - correct answers primary extended partition also called a*** logical partition ****in Windows, is located inside the primary extended partition bounds and contains a file system or other structured data. - correct answers secondary file system partition is a partition that contains a partition table and a secondary file system partition. - correct answers secondary extended partition Globally Unique ID - correct answers GUID GPT - correct answers GUID Partition Table contains a DOS partition table with one entry. The single entry is for a partition with a type of 0xEE that spans the entire disk. This partition exists so that legacy computers can recognize the disk as being used and do not try to format it. EFI does not actually use the partition, though. - correct answers Protective MBR Protective MBR GPT header Partition table Partition Area Backup area - correct answers Five areas in GPT Disk Each entry contains a starting and ending address, a type value, a name, attribute flags, and a GUID value. The 128- bit GUID is supposed to be unique for that system and is set when the partition table is created. - correct answers Partition table the largest area and contains the sectors that will be allocated to partitions. The starting and ending sectors for this area (not the each partition area) are defined in the GPT header - correct answers Partition Area contains a backup copy of the GPT header and partition table. It is located in the sector following the partition area. - correct answers Backup area provide a mechanism for users to store data in a hierarchy of files and directories. - correct answers File Systems First available: from the beginning Next available: from the last allocated cluster Best fit: searches for consecutive data units - correct answers Data unit allocation strategies(FAT) category contains the data that comprise the actual content of a file - correct answers content category contains the data that describe a file - correct answers file system (categ) category contains the data that describe a file - correct answers metadata category, or human interface category, contains the data that assign a name to each file - correct answers file name category contains data that provide special features - correct answers application RAM File - correct answers Two slack spaces between the end of the file and the end of the sector in which the file ends (slack spaces) - correct answers RAM Slack the remaining unused sectors in the data unit some OSes wipe the sectors, others ignore them (slack spaces) - correct answers File Slack

Content preview

Digital Forensics EXAM 1 Questions
With Detailed Correct Answers
relating to the use of scientific knowledge or methods in solving crimes - correct answers Forensic



A discipline that combines elements of law and computer science in order to collect and analyze
computer data from a variety of computer systems, networks, storage devices, and other devices using
digital communications as the source and flow of information in a way that is admissible as evidence in a
court of law. - correct answers Digital Forensics



True - correct answers Digital forensics includes computer forensics as well as forensics on all other
digital devices capable of storing digital data



*Network forensics

*Mobile device forensics

*Activity tracking device forensics, etc. - correct answers Forensic Tools



DF investigation does not need to have deepest understanding on theoretic knowledge on CS but must
have a familiarity with a wide range of subject matter. - correct answers True



e.g., computer network intrusion, DDOS attack - correct answers As a target of the crime



Cyber Stalking and bullying

Identity theft

Pirated computer software

Forgery or falsification of documents

Corporate fraud

Terrorism and national security - correct answers As an instrument of the crime

, Everything that enters a crime scene does two things. It leaves part of itself behind, and it takes part of
the scene with it. - correct answers Locard's Exchange Principle



According to some studies, almost 95 percent of criminals leave evidence which could be investigated
through computer forensic procedure. - correct answers True



Physical evidence cannot be wrong or wholly absent. Only human failure to find it, study and understand
it, can diminish its value - correct answers (Paul Kirk, 1953)



Things you can carry to court and show - correct answers Real evidence



To support or validate other evidence types - correct answers Testimonial evidence



Files, log, e-mail - correct answers Documentary evidence



To recreate or explain other evidence - correct answers Demonstrative evidence



Chat log, photo/video, image editing software, internet/SNS activity, movie files, relevant file and
directory names - correct answers Child Exploitation



Financial and asset data, credit card data, emails - correct answers Computer Fraud



Network user id and IP addresses, virus and spyware, system logs, etc. - correct answers Network
intrusion and hacking



How was the BTK killer caught - correct answers Name found in Floppy Disk



Evidence presented came from where he/she claims - correct answers Authenticity



was not altered in any way during examination, and there was no opportunity for it to have been
replaced or altered in the interim - correct answers Integrity

Document information

Uploaded on
August 8, 2026
Number of pages
14
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
RealGrades
4.0
(26)
Sold
197
Followers
52
Items
12327
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions