Forensics Flashcards
Evidence collection must be priorized by
volatility
First responders should first _____ and then _____.
assess and contain
To image a live system, ____ ____ images must be created
bit-level
Bit-level images must be created in _____
copies
Bit-level images must have ______
checksums
When creating a bit-level image of a static system, a _____ _____ must be used when connecting to a forensic workstation.
write-blocker
Documents that need to be created for forensics
Tracking log, chain of custody
In containment, systems may need to be….
Plugged out of the network, but not turned off ideally
Mitigations comes after ______
containment
classification is also called
data labeling
Modes of data acquisition for mobile devices
Physical (sim, memory cards and backups)
Logical: forensic image of storage volumes
Manual Access: Reviewing contents manually on live phone
Filesystem: deleted files and metadata