Chpt 19 Flashcards

1
Q

3 Requirements for evidence to be admissible

A

Must be 1) relevant, 2) material (related) to the case, and 3) competent (obtained legally)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SP 800-86

A

NIST guide to integrating forensic techniques into incident response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

4 major categories of evidence

A

Real, documentary, testimonial, and demonstrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Rules applied to documentary evidence

A

Best evidence - original copies are needed
Parol evidence - written agreements are assumed to contain all the terms of the agreement and no verbal agreements may modify the written agreement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

write blocker

A

hardware adapter used to prevent alteration to storage devices during media analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

memory dump

A

a file of memory of live systems used for in-memory analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ways to collect network traffic for an investigation

A

SPAN port on a switch, network tap hardware device, or software protocol analyzer on one of the communicating systems (less reliable)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

an FBI-led consortium of forensic analysts who produce detailed guidance on gathering digital evidence

A

The Scientific Working Group on Digital Evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RFC 1087

A

“Ethics and the Internet,” created by the Internet Architecture Board (IAB), describes unacceptable and unethics activity:
- seeks to gain unauthorized access
- disrupts the intended use of the internet
- wasted resources
- destroys the integrity of computer-based info
- compromised the privacy of users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

6 types of computer crimes

A

military and intelligence, business, financial, terrorist, grudge, thrill

How well did you know this?
1
Not at all
2
3
4
5
Perfectly