Digital Forensic Procedures Flashcards

1
Q

What is Digital Forensics?

A

process of investigating and analyzing digital devices and data to uncover evidence for legal purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 4 main phases of Digital Forensics?

A
  1. Identification
  2. Collection
  3. Analysis
  4. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain Identification in Digital Forensics

A

ensuring the safety of the scene, securing it to prevent any evidence contamination, and determining the scope of the evidence to be collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain Collection in Digital Forensics

A

Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Order of Volatility?

A

dictates the sequence in which data sources should be collected and preserved based on their susceptibility to modification or loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Chain of Custody?

A

documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment that it’s collected until it is presented in a court of law.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Disk Imaging?

A

involves creating a bit-by-bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is File Carving?

A

focuses on extracting files and data fragments from storage media without relying on the file system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain Analysis in Digital Forensics

A

systematically scrutinizing the data to uncover relevant information, such as potential signs of criminal activity, hidden files, timestamps, and user interactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Explain Reporting in Digital Forensics

A

Involves documenting the findings, processes and methodologies used during a digital forensic investigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Legal Hold?

A

formal notification that instructs employees to preserve all potentially relevant electronic data, documents, and records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly