IS4670 CHAPTER 12 TERMS & DEFINITIONS Flashcards
1
Q
- A project of the National Institute of Standards and Technology (NIST) that focuses on developing standards to ensure reliable results during forensic investigations. The project seeks to help forensic tool providers improve their products, keep the justice system informed, and make information available to government agencies and other organizations.
A
Computer Forensics Tool Testing (CFTT)
2
Q
- The validity, accuracy, usability, and integrity of data. This is an issue in live system forensics.
A
Data consistency
3
Q
- Forensic analysis of machines that have been shut down.
A
Dead system analysis
4
Q
- A complete copy of every bit of memory or cache recorded in permanent storage or printed on paper.
A
Dump
5
Q
- Checking to determine what hardware is present on a system.
A
Hardware fingerprinting
6
Q
- A live system forensics technique in which an investigator surveys the crime scene and simultaneously collects evidence and probes for suspicious activity. The purpose is to collect relevant evidence from a system to confirm whether an incident occurred.
A
Live response
7
Q
- The actual time during which a process takes place.
A
Real time
8
Q
- An image that results from acquiring a file system while it is being updated or changed by a program in process.
A
Slurred image
9
Q
- A live system forensics technique in which an investigator acquires a physical memory dump of the compromised system and transmits it to the data collection system for analysis.
A
Volatile memory analysis
10
Q
- A piece of hardware or software that allows a system to read data from an external drive at full speed. At the same time, it blocks any write commands to the external drive to prevent unauthorized modification or formatting of the drive being examined.
A
Write blocker