Chapter 4 Flashcards
What is required for evidence to be admissible in court?
Evidence must be obtained legally with a search warrant or consent
This includes proper documentation like the chain of custody form.
What organization sets standards and guidelines for forensic labs?
American Society of Crime Laboratory Directors (ASCLD)
ASCLD is a non-profit organization that promotes ethical practices in forensic labs.
What does ASCLD/LAB do?
Certifies labs, including computer forensics labs, for federal, state, and local agencies
ASCLD/LAB strives to maintain certain standards for forensics labs.
What international standard is relevant for digital forensic laboratories?
ISO/IEC 17025:2017
This standard provides guidelines for the competence of testing and calibration laboratories.
What is eDiscovery?
The detection of electronic data for litigation purposes
Involves retrieving electronically stored information (ESI) such as emails and spreadsheets.
What is the purpose of an evidence acquisition laboratory?
To extract evidence from storage devices for forensic analysis
Staff must be skilled in imaging software like FTK and EnCase.
What is a write-blocker?
A hardware device that allows reading data from a device without writing to it
Essential for preventing data alteration during forensic analysis.
What is the function of a Laboratory Information Management System (LIMS)?
Software for managing samples, data, and workflows in a lab
Offers case management, evidence tracking, and reporting.
What is the role of the Faraday Room in a forensic lab?
Blocks network connections to preserve evidence integrity
Prevents remote wipe and ensures evidence remains unaltered.
What is the default file system for modern Linux systems?
EXT4
EXT4 offers improved performance and reliability over its predecessors.
What is the purpose of the dd command in Linux?
To create an image of a partition
It copies and converts files in Unix operating systems.
True or False: Mobile device encryption has led to less invasive techniques in forensics.
False
It has led to more invasive techniques like chip-off.
What are some benefits of web hosting services provided by computer forensics departments?
- Centralized storage
- Efficient access
- Streamlined discovery
- Audit trails
These benefits enhance evidence management during investigations.
Fill in the blank: The _______ is a command-line utility used for reporting and manipulating a disk partition table.
fdisk
What does LiME stand for?
Linux Memory Extractor
It is an open-source tool for memory acquisition in Linux systems.
What is the primary concern for investigators when dealing with mobile devices?
Preventing remote wipe of the device
This is critical for maintaining evidence integrity.
What does the term ‘chain of custody’ refer to?
The process of maintaining and documenting the handling of evidence
It ensures the integrity of the evidence collected.
What is the significance of the Scientific Working Group on Digital Evidence (SWGDE)?
Shares research and sets standards for digital evidence investigations
Provides best practices for computer forensics examinations.
What are some examples of Linux distributions suitable for digital forensic analysis?
- Ubuntu
- Debian
- Kali Linux
Each distribution serves specific tasks within IT and forensic analysis.
What is the purpose of password-cracking software in a forensic lab?
To gain access to encrypted files and drives
This is essential for analyzing secure data during investigations.
What is necessary for a computer forensics laboratory to be certified?
Understanding of certification requirements
Certification involves meeting specific standards and practices in the field of computer forensics.
What are good practices for managing and processing evidence in a computer forensics laboratory?
Following established protocols and maintaining chain of custody
Good practices ensure the integrity and reliability of the evidence.
How should a computer forensics laboratory be structured?
With designated areas for evidence handling, analysis, and storage
Proper structure helps in maintaining organization and security.
What are the hardware and software requirements for a computer forensics laboratory?
Specialized forensic tools, secure storage solutions, and sufficient processing power
These requirements support effective evidence analysis and management.