3.2 Cyber Incident Response Flashcards
what is the best method to preserve evidence on a computer: bit stream backup or standard backup?
bit stream backup
what is the order of volatility from most volatile to least volatile?
registers, cache
swap space
routing table, ARP cache, process table, kernel statistics, and memory
temporary file systems
disk
remote logging and monitoring data that is relevant to the system in question
what are the FOUR documents/forms that should be part of forensic kit?
chain of custody form, incident response plan, incident form, call list/escalation list
what is a write blocker?
a tool that permits read-only access to data storage devices without compromising the integrity of the data
what is the purpose of imaging utilities included in a forensic kit?
to create a bit-level copy of drives
what are the NINE components that should be included in a forensic kit?
- digital forensics workstation
- write blockers
- cables
- drive adaptors
- wiped removable media
- camera
- crime tape
- tamper-proof seals
- documentation/forms
what is the purpose of the chain of custody form?
it will indicate who has handled the evidence, when they handled it, and the order in which the handler was in possession of the evidence
which condition must be true of the hash values of a file to prove the file is unaltered?
the hash values must remain the same
what is a SCADA device?
a system operating with coded signals over communication channels that provides control of remote equipment
what is the purpose of tamper-proof seals?
to ensure that the chain of custody is maintained
what is the purpose of hashing utilities included in a forensic kit?
to create a hash value of files so that you can prove that certain evidence has not been altered during your possession of the evidence
what is the proper life cycle of evidence steps?
collection, analysis, storage, court presentation, and return to owner
what is a digital forensics workstation?
a dedicated workstation for processing an investigation that includes special tools and utilities that make the process easier and more productive
what is the purpose of an incident form?
it is used to describe the incident in detail
why should the proper chain of custody be ensured?
so that evidence will be admissible in court