Forensics Flashcards

1
Q

What is digital forensics?

A

The process of identifying, preserving, analyzing, and presenting digital evidence for use in investigations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the first step in a digital forensics investigation?

A

Preservation—securing and isolating digital evidence to prevent tampering or loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is chain of custody?

A

A documented trail that shows the control, transfer, and analysis of digital evidence from collection to presentation in court.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the main types of digital forensics?

A

Computer forensics, mobile forensics, network forensics, and cloud forensics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a hash function in digital forensics?

A

A cryptographic algorithm used to create a unique digital fingerprint of a file to ensure its integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is live forensics?

A

The process of collecting digital evidence from a system that is still running.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is volatile data?

A

Information stored in RAM that is lost when a computer is powered off.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is file carving in digital forensics?

A

The technique of recovering deleted or corrupted files from a hard drive based on file signatures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a forensic image?

A

An exact bit-by-bit copy of a storage device, created to preserve the original evidence for analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the role of EnCase in digital forensics?

A

EnCase is a popular digital forensics tool used to collect and analyze evidence from various digital devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is network forensics?

A

The process of capturing, analyzing, and investigating network traffic to uncover cybercrimes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a forensic report?

A

A formal document summarizing the findings, methods, and conclusions of a digital forensics investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly