12B - Digital Forensics (Acquisition) Flashcards

1
Q

What is the Order of Volatility?

A

The order in which volatile data should be recovered from various storage locations and devices after a security incident occurs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the ISOC best practice guide to evidence collection and archiving outline?

A

The general order of volatility for recovering data after a security incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the first item in the general order of volatility?

A

CPU registers and cache memory (including cache on disk controllers, graphics cards, and so on).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is included in nonpersistent system memory?

A

Contents of RAM, including routing table, ARP cache, process table, and kernel statistics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What type of data is found on persistent mass storage devices?

A

Data on persistent mass storage devices (HDDs, SSDs, and flash memory devices):

  • Partition and file system blocks, slack space, and free space.
  • System memory caches, such as swap space/virtual memory and hibernation files.
  • Temporary file caches, such as the browser cache.
  • User, application, and OS files and directories.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are system memory caches?

A

Caches such as swap space/virtual memory and hibernation files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What type of data is stored in temporary file caches?

A

Data such as the browser cache.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What types of files and directories are included in user, application, and OS data?

A

User files, application files, and operating system files and directories.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is included in remote logging and monitoring data?

A

Data collected from remote logging and monitoring systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the physical configuration and network topology refer to?

A

The arrangement and setup of physical devices and network structure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What types of media are considered archival media?

A

Archival media and printed documents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly