Digital Evidence Flashcards
- What is digital evidence? Choose all that applies
● is any stored or transmitted data in binary format that may be useful in a criminal or civil investigation.
● The binary format is how computers store information and is rendered in bits (either 0s and 1s); binary is used in almost all modern computers and digital devices.
● can be found on hard drives, cell phones, mobile storage media, networks, and many other sources.
● is any stored or transmitted data in binary format that may be useful in a criminal or civil investigation.
● The binary format is how computers store information and is rendered in bits (either 0s and 1s); binary is used in almost all modern computers and digital devices.
● can be found on hard drives, cell phones, mobile storage media, networks, and many other sources.
- Define metadata? Choose all that applies.
● The data about data - a set of data that describes and gives information about other data.
● aids in the classification of the intended information, providing identification, location, time, author, archiving, and contextual information about the file.
● Like a dictionary.
( (all of it)
- Define data carve. Choose all that applies.
● Used to reconstruct the files, their structure and content to be recovered if system metadata is lost or corrupted.
● also known as file carving, is the forensic technique of reassembling files from raw data fragments when no filesystem metadata is available. It is a common procedure when performing data recovery, after a storage device failure, for instance.
(all of it)
- Below are the components for a computer. Select the incorrect one.
● Hardware & software ● A case (circuit boards, storage media, interface connections) ● Display device ● Keyboard ● Printer ● Pointing device
● Printer
5. Below are examples of forensically valuable data, select the one that does not apply. ● Applications ● Pointing device ● Documents ● Emails ● Databases ● Browsing history ● Maintenance, event logs.
Pointing device
6. Which type of storage device is this? …… are data storage devices that have an external logic board, connections to external sources of information and power, and some form of storage media. ● Hard drives ● Flash drives ● Memory Cards ● Sim Card
. Hard drive
- Which type of storage device is this? ……. are small removable data storage devices with USB (universal serial bus) connections; their size makes them easy to transport and, therefore, conceal.
● Hard drives
● Flash drives
● Memory Cards
Flash drive/thumb drive
- Which type of storage device is this? ……. are very small storage devices typically used in digital cameras, but can also be used with tablets, computers, cell phones, video game consoles, and other electronic devices.
● Hard drives
● Flash drives
● Memory Cards
● SIM Card (A type of memory card, Subscriber Identification Module.)
Memory Card
9. Electronic Control Units (ECUs) help to monitor and control systems and subsystems, like traction control and diagnostics for maintenance in motor vehicles. ECU stores information except one. ● Vehicle data ● Passenger occupancy ● Crash data called event data record. ● Phone data
Phone data
- WHAT are the FIVE Steps/Phases on Processing Digital Evidence?
I C T A R
● Identification ● Collection/Acquisition ● Transportation ● Analysis/Examination ● Report
- TRUE or FALSE: Digital evidence is latent evidence.
True- the bits of data stored on the device or being transmitted through wires or the air cannot be immediately seen.
- Identification Phase:
● Key concept- 1st to identify
● 2nd identify the type of digital evidence that is stored on the physical evidence item and their relevance to the matter.
1st to identify the Types that contain evidence that may be of Probative nature.
2nd identify the type of digital evidence that is stored on the physical evidence item and their Relevance to the matter.
- How do you prevent/secure cell phones from being tampered?
● Place the phone on aeroplane mode- to cut off wifi signals.
● Wrap three layers of foil
- TRUE or FALSE: When moving a digital device like a computer during collection the device should be hibernated or powered off first.
True
- True or False: Leave cell phones in the power state (on or off) in which they were found.
True