CHFI Module 1 Questions and Answers Already Passed
CHFI Module 1 Questions and Answers Already Passed Computer Forensics Deals with crimes committed on computing devices. Gathers, preserves, maintains, and interprets data which could be used as evidence in a court of law Types of Cybercrimes Internal: Primary threats with direct access to fragile data External: Secondary threats which utilize exploits to get the sensitive data Challenge 1: Speed Crimes happen so fast but there must be a bunch of hoops for a Forensics investigator to actually gather the data Challenge 2: Anonymity The internet is so large, attacks can be from anyone anywhere. The bad actors sometimes use tools to hide their identity Challenge 3: Volatile nature of evidence Evidence can disappear if handled improperly, such as if the computer is shut down. Needs special tools to gather Challenge 4: Anti-Digital Forensics (ADF) Encryption to hide evidence so it cannot be gathered by some tools Challenge 5: Limited Legal Understanding Victims generally don't know the laws, so they don't defend themselves against them Challenge 6: Global origin and difference in laws Since attackers can be anywhere, the laws where they reside differ from where the investigator is from, and must be knowledgeable in the foreign laws Criminal Cases Legal cases brought by the state intending to punish violations of the law. These cases normally involve the possibility of imprisonment Civil Cases Court cases that involve a private dispute arising from such matters as accidents, contractual obligations, and divorce. These cases result in monetary damages. Enterprise Theory of Investigation (ETI) A standard investigative tool of the FBI that focuses on criminal enterprise and attacks the structure of the criminal enterprise rather than criminal acts viewed as isolated incidents. Lockard's Exchange Principle Any time a crime scene is entered/left, a part of the scene is taken/added Types of Digital Evidence Volatile and Non-volatile data Characteristics of Digital Evidence This evidence must have some characteristics to be disclosed in the court of law. The characteristics include: Admissible, Authentic, Complete, Reliable, Believable User Created Files Files including Media, Documents, internet bookmarks, etc User Protected Files Compressed, misnamed, encrypted, password protected, and hidden files Computer Created Files Automated backup files, Log, Config, cookies, swap files, system files, history files, etc Best Evidence Rule The requirement that the original copy of a written agreement be submitted into evidence Rule 105 Limited Admissibility When evidence which is admissible as to one party or for one purpose but not admissible as to another party or for another purpose is admitted, the court, upon request, shall restrict the evidence to its proper scope and instruct the jury accordingly. Hearsay Rule Hearsay can be taken in as evidence if it meets certain criteria. What is Hearsay A statement made by some person who is not testifying in court for the purpose of proving the truth of that statement
Información del documento
- Subido en
- 9 de marzo de 2024
- Número de páginas
- 8
- Escrito en
- 2023/2024
- Tipo
- Examen
- Contiene
- Preguntas y respuestas