4.5 key aspects of digital forensics Flashcards
1
Q
order of volatility
A
most volatile data to capture first:
CPU, Ram
Memory, tables, kernel
temporary file systems
disk
remote data
physical configurations
archival media
2
Q
swap/pagefile
A
a system file that creates temporary storage space on a hard disk or solid-state drive.
3
Q
snapshot
A
for virtual machines
point-in-time system image
4
Q
cache
A
store data for later use and is cached in CPU, disk, internet, etc.
5
Q
hashing integrity
A
digital fingerprint for cryptographic integrity thru hashing
6
Q
checksum integrity
A
simple integrity check
protects from accidental changes during transmission
7
Q
provenance integrity
A
documentation of origination
data handling