Computer Forensics Flashcards

1
Q

What is Computer Forensics?

A

Set of methodological procedures and techniques that help identify, gather, preserve, extract, interpret, document and present evidence from computing equipment, such that any discovered evidence is acceptable during a legal and/or administrative proceeding.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the objectives of Computer Forensics?

A
  1. Identify, gather and preserve the evidence.
  2. Estimate the potential impact.
  3. Assess the intent of the perpetrator.
  4. Minimize the losses (tangible and intangible).
  5. Protect from the similar incidents in the future.
  6. Support the prosecution of the perpetrator.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Impact of Cybercrimes at the Organizational Level

A
  1. Loss of confidentiality, integrity and availability.
  2. Data theft.
  3. Disruption of business activities.
  4. Loss of customer and stakeholder trust.
  5. Reputational damage.
  6. Financial losses.
  7. Penalties arising from the failure to comply with regulations.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Digital Evidence?

A

Any information of probative value that is either stored or transmitted in a digital form.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does Locard’s Exchange Principle say?

A

Anyone or anything entering a crime scene takes something of the scene with them, and leaves something of themselves behind when they leave.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the rules of evidence?

A
  • Understandable
  • Admissible
  • Authentic
  • Reliable
  • Complete
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does it mean that evidence has to be complete?

A

Prove the attacker’s actions of his/her innocence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the best evidence rule?

A

The court only allows the original evidence of a document, photograph or recording at the trail rather than a copy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly