CHFI Module 1 Questions & Answers | Latest update 100% Solved
CHFI Module 1 Questions & Answers | Latest update 100% Solved Computer Forensics - Deals with crimes committed on computing devices. Gathers, preserves, maintains, and interprets data which could be used as evidence in a court of law Types of Cybercrimes - Internal: Primary threats with direct access to fragile data External: Secondary threats which utilize exploits to get the sensitive data Challenge 1: Speed - Crimes happen so fast but there must be a bunch of hoops for a Forensics investigator to actually gather the data Challenge 2: Anonymity - The internet is so large, attacks can be from anyone anywhere. The bad actors sometimes use tools to hide their identity Challenge 3: Volatile nature of evidence - Evidence can disappear if handled improperly, such as if the computer is shut down. Needs special tools to gather Challenge 4: Anti-Digital Forensics (ADF) - Encryption to hide evidence so it cannot be gathered by some tools Challenge 5: Limited Legal Understanding - Victims generally don't know the laws, so they don't defend themselves against themChallenge 6: Global origin and difference in laws - Since attackers can be anywhere, the laws where they reside differ from where the investigator is from, and must be knowledgeable in the foreign laws Criminal Cases - Legal cases brought by the state intending to punish violations of the law. These cases normally involve the possibility of imprisonment Civil Cases - Court cases that involve a private dispute arising from such matters as accidents, contractual obligations, and divorce. These cases result in monetary damages. Enterprise Theory of Investigation (ETI) - A standard investigative tool of the FBI that focuses on criminal enterprise and attacks the structure of the criminal enterprise rather than criminal acts viewed as isolated incidents. Lockard's Exchange Principle - Any time a crime scene is entered/left, a part of the scene is taken/added Types of Digital Evidence - Volatile and Non-volatile data Characteristics of Digital Evidence - This evidence must have some characteristics to be disclosed in the court of law. The characteristics include: Admissible, Authentic, Complete, Reliable, BelievableUser Created Files - Files including Media, Documents, internet bookmarks, etc User Protected Files - Compressed, misnamed, encrypted, password protected, and hidden files Computer Created Files - Automated backup files, Log, Config, cookies, swap files, system files, history files, etc Best Evidence Rule - The requirement that the original copy of a written agreement be submitted into evidence Rule 105 - Limited Admissibility When evidence which is admissible as to one party or for one purpose but not admissible as to another party or for another purpose is admitted, the court, upon request, shall restrict the evidence to its proper scope and instruct the jury accordingly. Hearsay Rule - Hearsay can be taken in as evidence if it meets certain criteria. What is Hearsay - A statement made by some person who is not testifying in court for the purpose of proving the truth of that statement When it isn't Hearsay - The statement was made prior to the court date, and is the same when the witness is called. A statement made under oath that contradicts the declarant's statement.Rule 803 - Hearsay Exceptions, Availability of Declarant Immaterial Rule 804 - Hearsay Exceptions; Declarant Unavailable (a) Criteria for Being Unavailable. A declarant is considered to be unavailable as a witness if the declarant: (1) is exempted from testifying about the subject matter of the declarant's statement because the court rules that a privilege applies; (2) refuses to testify about the subject matter despite a court order to do so; (3) testifies to not remembering the subject matter; (4) cannot be present or testify at the trial or hearing because of death or a then-existing infirmity, physical illness, or mental illness; or (5) is absent from the trial or hearing and the statement's proponent has not been able, by process or other reasonable means, to procure: (A) the declarant's attendance, in the case of a hearsay exception under Rule 804(b)(1) or (6); or (B) the declarant's attendance or testimony, in the case of a hearsay exception under Rule 804(b)(2), (3), or (4). A declarant is not unavailable as a witness if exemption, refusal, inability, or absence is due to the procurement or wrong doing causing the declarant's unavailability as a witness in order to prevent the declarant from attending or testifying. Rule 1001 - Definitions Writings and recordings: letters, words, numbers, photos, voicePhotographs: Including X-rays and video Original: The first of the type of evidence presented Duplicate: Copy of the evidence by photography, re-recording, or otherwise Rule 1002 - Requirement of the Original-An original writing, recording or photograph is required in order to prove its content unless these rules or a federal statute provides otherwise Rule 1003 - Admissibility of Duplicates A duplicate is admissible to the same extent as the original unless a genuine question is raised about the original's authenticity or the circumstances make it unfair to admit the duplicate. Rule 1004 - A copy of the original can be accepted if the original is lost or destroyed, the opponent has the original, the original is not obtainable, or if the original is not closely related to a controlling issue Scientific Working Group on Digital Evidence (SWGDE) - SWGDE states that in order to ensure that digital evidence is collected, preserved, examined or transferred in a manner safeguarding the accuracy and reliability of the evidence, law enforcement and forensic organizations must establish and maintain an effective quality system Forensic Readiness - Refers to an organization's ability to make optimal use of digital evidence in a limited period of time with minimal investigative costsIncident Response - The plan of action if a security breach were to occur. Minimizes damages and defends future attacks and fixes previous ones. List of Forensic Investigator's Roles and Responsibilities - Accesses damages, recovers data, gathers undamaged evidence, creates non altered copies of the original evidence, describes significance of the evidence, analyzes evidence, discloses potential attack methods and offers ways of defending from them Forensic Investigators - By virtue of his/her skills and experience, helps organizations and law enforcement agencies investigate and prosecute the perpetrators of cyber crimes Code of Ethics of a Forensic Investigator - The code of ethics are the principles stated to describe the expected behavior of an investigator while handling a case Digital Evidence - any information of probative value stored or transmitted in digital form
Document information
- Uploaded on
- April 1, 2024
- Number of pages
- 6
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers