5.5 Basic concepts of forensics Flashcards

1
Q

Order of volatility

A

Order of volatility of evidence from more to less:

  • CPU registers and cache memory
  • Routing table, arp cache, process table, kernel statistics
  • Memory (RAM)
  • Temporary file systems
  • Disk
  • Remote logging and monitoring data
  • Physical configuration and network topology
  • Archival media
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Chain of custody

A

Form records where, when, and who collected the evidence, who subsequently handled it, and where it was stored.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Legal hold

A

Refers to the fact that information that may be relevant to a court case must be preserved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Capture system image

A

The process of obtaining a forensically clean copy of data from a device held as evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Task hashes

A

Demonstrates that analysis has been performed on an image of the data that is identical to the data present on the disk and that neither data set has been tampered with.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Preservation

A

Best practice is that evidence should be preserved and documented at the crime scene in its original state; that is, computers or other devices that are off should not be switched on and those that are on should not be switched off.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Recovery

A

Analyzing information from hard drives taken as evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Strategic intelligence/counterintelligence gathering

A

Counterintelligence is the process of information gathering to protect against espionage and hacking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly