392 - Computer Forensic Investigations Flashcards

1
Q

Who is the owner of Order 392 - Computer Forensic Investigations

A

Commanding Officer of Computer Forensics Investigations Unit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CFI: All requests for digital examination must be accompanied with a formal request on a _____ that can be downloaded from their Unit website.

A

CFI Unit request form

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CFI: All digital media seized or obtained for examination must be accompanied by a _____ or _____

A

written consent form or a search warrant (to include affidavit).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CFI: Verbal consent must be documented on an _____ or _____ from the witnessing investigator.

A

Intradepartmental Correspondence (P-0004) or via departmental email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

All digital media brought to the CFI Unit must have been previously _____ and _____

A

submitted to the Property & Evidence Facility and assigned a property control number.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CFI: Evidence delivery is the responsibility of the _____

A

submitting/requesting officer/detective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

If data, image, or digital evidence is in plain view on a computer or mobile device screen, the officer/detective should if possible_______, without manipulating the digital device and consult a _____

A

take a photograph of what is in plain view

digital forensic examiner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

If the digital device is OFF, _____.

A

leave it OFF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If the digital device is ON, document _____, ____ and _____, without ______.

A

open screens, time and dates

imputing data into the device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

If the digital device is ON, do NOT type or input anything into the device. Exception: There may be times when this cannot be avoided. If this happens, _____ and _____.

A

document every step used and document why this step was necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When collecting a desktop computer: if it is ON,_____ and _____

A

leave it ON and simply unplug the power cord from the back of the computer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

if the computer is on and there is an articulable belief that hard drive(s) are encrypted, do NOT unplug or power off the computer. Instead, _____

A

consult with the on-call digital forensic examiner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When collecting a laptop computer: if it is ON, _____ and _____, _____.

A

leave it ON and remove the battery first, then the power cord

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Cellular phones and mobile devices (eReaders, tablets, GPS, etc.) should be collected in the same manner as the rules listed above; however, it is imperative to ______ before turning the device off

A

obtain the password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Forensic examinations can have extensive processing times that are subject to change without notice, and owners/agents of electronic devices should NOT be given specific time frames on the completion of the examination. The owner/agent can be informed that _____

A

they will be contacted upon the completion of the examination.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly