Chapter 1 Flashcards

1
Q

What is the definition of forensics?

A

The use of science and technology to investigate and establish facts in criminal or civil courts of law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the subject of computer forensics?

A

The extraction of data in a consistent, scientific manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is latent evidence?

A

Evidence that can take many forms.

Laten = hidden such as fingerprints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the definition of computer forensics according to US-CERT?

A

Forensics is the process of using scientific knowledge for collecting, analyzing, and presenting evidence to the courts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does computer forensics generally consider?

A

The use of analytical and investigative techniques to identify, collect, examine and preserve evidence/information which is magnetically stored or encoded.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the objective of computer forensics?

A

To recover, analyze, and present computer-based material as evidence in a court of law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What devices can be the subject of computer forensics?

A

Both network servers, personal computers, laptops and smartphones, routers, tablets, printers, GPS devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the goal of computer forensics?

A

To obtain evidence that can be used in some legal proceeding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the first step in computer forensics?

A

Understanding computer hardware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is one issue with the current practice of forensics?

A

Too many individuals want to enter the field without adequate computer backgrounds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the basic knowledge required for mastering forensics?

A

Understanding of computer hardware
Understanding of the operating system
Understanding of computer networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the assumption made while presenting the material in the book?

A

The reader has zero knowledge of computers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a key factor in becoming better at computer forensics?

A

Knowing more about computers and networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What changes very slowly, if at all, in the field of computer forensics?

A

The various file systems and the role of volatile and non-volatile memory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the first step in computer forensics investigation?

A

Collecting the evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What determines if the evidence is admissible in court?

A

How you collect the evidence

17
Q

What is the most time-consuming part of a forensic investigation?

A

Analyzing the data

18
Q

What is the final step in a forensic investigation?

A

Presenting the evidence

19
Q

What are the two most basic forms of presenting evidence in a forensic investigation?

A

Expert report and expert testimony

20
Q

What is an expert report in the context of forensic investigation?

A

A document that lists the tests conducted, findings, and conclusions

21
Q

What is included in an expert report along with the tests conducted, findings, and conclusions?

A

The expert’s curriculum vitae (CV)

22
Q

What is the first step in creating an expert report?

A

Listing the expert’s qualifications

23
Q

What is the purpose of an expert report in computer forensics?

A

To detail the analysis used and tools applied

24
Q

What are the two scenarios in which an expert witness gives testimony?

A

Deposition and trial

25
Q

What is U.S. Federal Rule 702 about?

A

Defining what an expert is and what expert testimony is

26
Q

What does U.S. Federal Rule 703 state about an expert?

A

An expert may base an opinion on facts or data

27
Q

What does U.S. Federal Rule 704 state about an expert’s opinion?

A

An expert’s opinion is not objectionable just because it embraces an ultimate issue

28
Q

What does U.S. Federal Rule 705 state about an expert’s testimony?

A

An expert may state an opinion without first testifying to the underlying facts or data

29
Q

What does U.S. Federal Rule 706 state about expert witnesses?

A

This rule covers the appointment of neutral experts used to advise the court

30
Q
A