4.5 Key aspects of digital forensics Flashcards

1
Q

Digital forensics: what is digital forensics?

A

The process of collecting and protecting information relating to an intrusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Digital forensics: is there a feamework for digital forensics?

A

Yes, RFC 3227 - Guidelines for Evidence Collection and Archiving

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Digital forensics: what are the 3 steps of digital forensics process?

A

Acquisition, analysis and reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Digital forensics: why documentation is important in digital forensics?

A

For legal reason, the documentation also needs to be kept a certain amount of time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Digital forensics: what is chain of custody ?

A

A process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the documents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Managing evidence: how to ensure data integrity when collecting data ?

A

By hashing it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Managing evidence: how to preserve data that has been collected ?

A

Create a copy and isolate it. Work from copies of the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Managing evidence: what is E-discovery?

A

Refers to gathering data without consideration of intent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly