Digital Evidence Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

What is the hardware?

A

physical components of a computer we can see and touch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the software?

A

applications and programs found on the hardware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name the 3 commonly found software on a computer with examples.

A

Operating system (windows or mac)
Word-Processing (word)
Web-browsing (explorer or firefox)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When someone buys Microsoft office on a CD, the CD contains the ____ which can be transferred to the ____ (___) on your computer.

A

software
hardware
HDD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the ROM? What letters stand for and what role?

A

Read-Only memory

  • stored firmware that starts boot sequence (starts computer)
  • Contains the BIOS: basic input-output system
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the role of the BIOS?

A

starts booting process and communication with devices such as keyboard, monitor, printer, disk drives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

You should never boot a computer under investigation on the _______.

A

original HDD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What CPU stands for and what is its role?

A

central processing unit
processor/brain of the computer.
All operations run through CPU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does RAM stand for and what is its role?

A
Random-access memory 
Volatile memory (temporary) so that computer doesn't always have to go through CPU and HDD. 
Permanently lost if close computer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is stored on the Hard disk drive?

A

Operating system (Windows)
Programs (Word, Explorer)
Data files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

HDD gives a _____ record of the info, even when computer ____.

A

permanent

off

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What happens when turning on the computer? 7 steps

A

1- power from the motherboard goes through the power supply.
2- A POST (power-on self-test) is performed by the ROM.
3- The flash ROM tests the motherboard to make sure the hardware is there and that it follows a programmed boot order.
4- The HDD is sent control. It locates the first sector and determines its layout. + boots the operating system.
5- Now have the desktop
6- When click on the desktop: CPU locates Excel on the HDD and loads it into RAM (with system bus). Sends output to the monitor through the video controller of the motherboard.
7- Info you type is stored in the RAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens when printing documents?

A

data is taken from RAM, processed by CPU, put in printable format and sent through system bus to the external port (where printer is)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What happens when saving documents?

A

from RAM, processed CPU passed to HDD through system bus and written on the HDD.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

One HDD could have __ (#) _____ making look like # disks. All ____ from one another.

A

5
partitions
5
independant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The HDD is divided into 4: name each part

A

sectors
clusters
tracks
cylinders

17
Q

Each device will be ____ to view:
_____
______ to any other devices
_______

A

photographed
monitor(if running)/screen
connections
serial numbers if needed

18
Q

What are the 3 decisions that must be taken before the equipment is seized?

A

1- live acquisition of the data?
2- System shutdown?
3- pulldown the plug?

19
Q

What are the 2 scenarios for mobile devices?

A

1- turned off: cell tower location, call logs and remove battery
2- Faraday bag if cant turn it off.

20
Q

Wireless devices will first be examined in ______ or switched into the _____ and then in ____ mode.
The device switched on ___ mode (write blocking software) and ___ of the original storage on a new storage device.

A

isolation chamber
faraday bag
airplane

read-only
duplicate

21
Q

For a computer, the ___ will be removed and an image of it will be created.

A

HDD

22
Q

Analyst will look for ____ and ____ ____ files.

And 6 others:

A
deleted and partially deleted. 
data/work product files
swap files data
temporary files
slack space
unallocated space
defragmenting
23
Q

What are the 7 things look for on internet?

A
internet cache 
internet cookies
internet history
bookmark and favorite places
chat convo
instant messages
emails
24
Q

Emails can give us ______, which can lead to an address.

A

IP address

25
Q

What are the 3 main limitations of digital evidence?

A

encryption
proprietary systems
legal, privacy laws.