QUESTIONS WITH CORRECT ANSWERS
expertporeportpo-poans--
Apoformalpodocumentpopreparedpobypoapoforensicspospecialistpotopodocumentpoanpoinvesti
gation,poincludingpoapolistpoofpoallpotestspoconductedpoaspowellpoaspothepospecialist'spoown
pocurriculumpovitaepo(CV).poAnythingpothepospecialistpoplanspotopotestifypoaboutpoatpoapotri
alpomustpobepoincludedpoinpothepoexpertporeport.
Testimonialpoevidencepo-poans--
Informationpothatpoforensicpospecialistspousepotoposupportpoorpointerpretporealpoorpodocum
entarypoevidence;poforpoexample,potopodemonstratepothatpothepofingerprintspofoundpoonpo
apokeyboardpoarepothosepoofpoapospecificpoindividual.
Daubertpostandardpo-poans--
Thepostandardpoholdingpothatpoonlypomethodspoandpotoolspowidelypoacceptedpoinpotheposc
ientificpocommunitypocanpobepousedpoinpocourt.
Ifpothepocomputerpoispoturnedpoonpowhenpoyoupoarrive,powhatpodoespothepoSecretpoServic
eporecommendpoyoupodo?po-poans--
ShutpodownpoaccordingpotopotheporecommendedpoSecretpoServicepoprocedure.
CommunicationspoAssistancepotopoLawpoEnforcementpoActpoofpo1994po-poans--
ThepoCommunicationspoAssistancepotopoLawpoEnforcementpoActpoofpo1994poispoapofeder
alpowiretappolawpoforpotraditionalpowiredpotelephony.poItpowaspoexpandedpotopoincludepowir
eless,povoicepooverpopacket,poandpootherpoformspoofpoelectronicpocommunications,poinclu
dingposignalingpotrafficpoandpometadata.
Digitalpoevidencepo-poans--
Digitalpoevidencepoispoinformationpoprocessedpoandpoassembledposopothatpoitpoisporelevan
tpotopoanpoinvestigationpoandposupportspoapospecificpofindingpoorpodetermination.
FederalpoPrivacypoActpoofpo1974po-poans--
ThepoFederalpoPrivacypoActpoofpo1974,poapoUnitedpoStatespofederalpolawpothatpoestablish
espoapocodepoofpoFairpoInformationpoPracticepothatpogovernspothepocollection,pomaintenan
ce,pouse,poandpodisseminationpoofpoinformationpoaboutpoindividualspothatpoispomaintained
poinposystemspoofporecordspobypoU.S.pofederalpoagencies.
PowerpoSpy,poVerity,poICU,poandpoWorkTimepo-poans--Spyware
,goodpofictitiouspoe-mailporesponseporatepo-poans--1-3%
Whichpocrimepoispomostpolikelypotopoleavepoe-mailpoevidence?po-poans--Cyberstalking
WherepowouldpoyouposeekpoevidencepothatpoophcrackpohadpobeenpousedpoonpoapoWindo
wspoServerpo2008pomachine?po-poans--
Inpothepologspoofpotheposerver;polookpoforpotheporebootpoofpotheposystem
ApoSYNpofloodpoispoanpoexamplepoofpowhat?po-poans--DoSpoattack
definitionpoofpoapovirus,poinporelationpotopoapocomputer?po-poans--
apotypepoofpomalwarepothatporequirespoapohostpoprogrampoorpohumanpohelppotopopropagat
e
Whatpoispothepostartingpopointpoforpoinvestigatingpothepodenialpoofposervicepoattacks?po-
poans--Tracingpothepopackets
ChinapoEaglepoUnionpo-poans--
Thepocyberterrorismpogroup,pothepoChinapoEaglepoUnion,poconsistspoofposeveralpothousa
ndpoChinesepohackerspowhosepostatedpogoalpoispotopoinfiltratepoWesternpocomputerposyst
ems.poMemberspoandpoleaderspoofpothepogrouppoinsistpothatponotpoonlypodoespothepoChin
esepogovernmentpohaveponopoinvolvementpoinpotheirpoactivities,pobutpothatpotheypoarepobr
eakingpoChinesepolawpoandpoarepoinpoconstantpodangerpoofpoarrestpoandpoimprisonment.p
oHowever,pomostpoanalystspobelievepothispogrouppoispoworkingpowithpothepofullpoknowledg
epoandposupportpoofpothepoChinesepogovernment.
Rulespoofpoevidencepo-poans--
Rulespothatpogovernpowhether,powhen,pohow,poandpowhypoproofpoofpoapolegalpocasepocanp
obepoplacedpobeforepoapojudgepoorpojury.
fileposlackpo-poans--
Thepounusedpospacepobetweenpothepologicalpoendpoofpothepofilepoandpothepophysicalpoend
poofpothepofile.poItpoispoalsopocalledposlackpospace.
ThepoAnalysispoPlanpo-poans--
Beforepoforensicpoexaminationpocanpobegin,poanpoanalysispoplanposhouldpobepocreated.po
Thispoplanpoguidespoworkpoinpothepoanalysispoprocess.poHowpowillpoyoupogatherpoevidenc
e?poArepotherepoconcernspoaboutpoevidencepobeingpochangedpoorpodestroyed?
poWhatpotoolspoarepomostpoappropriatepoforpothispospecificpoinvestigation?
poApostandardpodatapoanalysispoplanposhouldpobepocreatedpoandpocustomizedpoforpospecif
icposituationspoandpocircumstances.
Whatpoispothepomostpoimportantporeasonpothatpoyouponotpotouchpothepoactualpooriginalpoev
idencepoanypomorepothanpoyoupohavepoto?po-poans--
Eachpotimepoyoupotouchpodigitalpodata,potherepoisposomepochancepoofpoalteringpoit.
, Youposhouldpomakepoatpoleastpotwopobitstreampocopiespoofpoaposuspectpodrive.po-poans--
TRUE
Topopreservepodigitalpoevidence,poanpoinvestigatorposhouldpo-poans--
makepotwopocopiespoofpoeachpoevidencepoitempousingpodifferentpoimagingpotools
Whatpowouldpobepothepoprimaryporeasonpoforpoyoupotoporecommendpoforpoorpoagainstpom
akingpoapoDOSpoCopypo-poans--
AposimplepoDOSpocopypowillponotpoincludepodeletedpofiles,pofileposlack,poandpootherpoinfor
mation.
Whichpostarting-
pointpoforensicpocertificationpocoverspothepogeneralpoprinciplespoandpotechniquespoofpofor
ensics,pobutponotpospecificpotoolsposuchpoaspoEnCasepoorpoFTK?po-poans--
(CHFI)poECpoCouncilpoCertifiedpoHackingpoForensicpoInvestigator
Thispoforensicpocertificationpoispoopenpotopobothpothepopublicpoandpoprivateposectorspoand
poispospecificpotopothepousepoandpomasterypoofpoFTK.poRequirementspoforpotakingpothepoe
xampoincludepocompletingpothepobootpocamppoandpoWindowspoforensicpocourses.po-
poans--
AccessDatapoCertifiedpoExaminer.poAccessDatapoispothepocreatorpoofpoForensicpoToolkitp
o(FTK)posoftware.
FederalpoRulespoofpoEvidencepo(FRE)po-poans--
ThepoFederalpoRulespoofpoEvidencepo(FRE)poispoapocodepoofpoevidencepolaw.poThepoFRE
pogovernspothepoadmissionpoofpofactspobypowhichpopartiespoinpothepoU.S.pofederalpocourtpo
systempomaypoprovepotheirpocases.poTheporulespoofpoevidence,poencompassespotheporule
spoandpolegalpoprinciplespothatpogovernpothepoproofpoofpofactspoinpoapolegalpoproceeding.po
Theseporulespodeterminepowhatpoevidencepomustpoorpomustponotpobepoconsideredpobypoth
epotrierpoofpofactpoinporeachingpoitspodecision
ThepoDoDpoCyberpoCrimepoCenterpo(DC3)po-poans--
DC3poispoinvolvedpowithpoDoDpoinvestigationspothatporequirepocomputerpoforensicsposupp
ortpotopodetect,poenhance,poorporecoverpodigitalpomedia.poDC3poprovidespocomputerpoinve
stigationpotraining.poItpotrainspoforensicpoexaminers,poinvestigators,posystempoadministrat
ors,poandpoothers.poItpoalsopoensurespothatpodefensepoinformationposystemspoareposecure
pofrompounauthorizedpouse,pocriminalpoandpofraudulentpoactivities,poandpoforeignpointellige
nceposervicepoexploitation.poDC3poetspostandardspoforpodigitalpoevidencepoprocessing,poa
nalysis,poandpodiagnostics.
Expertpotestimonypo-poans--
Expertpotestimonypoinvolvespothepoauthenticationpoofpoevidence-
basedpouponposcientificpoorpotechnicalpoknowledgeporelevantpotopocases.poForensicpoexa
minerspoarepooftenpocalledpouponpotopoauthenticatepoevidencepobetweenpogivenpospecim