IS4670 CHAPTER 12 TERMS & DEFINITIONS Flashcards

1
Q
  • A project of the National Institute of Standards and Technology (NIST) that focuses on developing standards to ensure reliable results during forensic investigations. The project seeks to help forensic tool providers improve their products, keep the justice system informed, and make information available to government agencies and other organizations.
A

Computer Forensics Tool Testing (CFTT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  • The validity, accuracy, usability, and integrity of data. This is an issue in live system forensics.
A

Data consistency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
  • Forensic analysis of machines that have been shut down.
A

Dead system analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
  • A complete copy of every bit of memory or cache recorded in permanent storage or printed on paper.
A

Dump

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  • Checking to determine what hardware is present on a system.
A

Hardware fingerprinting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  • A live system forensics technique in which an investigator surveys the crime scene and simultaneously collects evidence and probes for suspicious activity. The purpose is to collect relevant evidence from a system to confirm whether an incident occurred.
A

Live response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
  • The actual time during which a process takes place.
A

Real time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
  • An image that results from acquiring a file system while it is being updated or changed by a program in process.
A

Slurred image

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  • A live system forensics technique in which an investigator acquires a physical memory dump of the compromised system and transmits it to the data collection system for analysis.
A

Volatile memory analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  • A piece of hardware or software that allows a system to read data from an external drive at full speed. At the same time, it blocks any write commands to the external drive to prevent unauthorized modification or formatting of the drive being examined.
A

Write blocker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly