IS4670 CHAPTER 3 TERMS & DEFINITIONS Flashcards

1
Q

Attempts to adversely affect the existence, amount, and quality of evidence from a crime scene or to make the analysis and examination of evidence difficult or impossible to conduct.

A

Anti-forensics -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Continuity of evidence that makes it possible to account for all that has happened to evidence between its original collection and its appearance in court, preferably unaltered.

A

Chain of custody -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Raw numbers, pictures, and other “stuff ” that may or may not have relevance to a particular event or incident under investigation.

A

Data -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A plan that lists the types of data to be collected and describes the expected sources for the data. It should also list any anticipated problems as well as recommended strategies to deal with those problems.

A

Data analysis plan -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Information such as a chart that helps explain other evidence to a judge and jury.

A

Demonstrative evidence -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Written evidence that must be authenticated, such as a printed report or a log file.

A

Documentary evidence -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Anything that changes or destroys digital evidence between the time the evidence is created and when the case goes to court. An action that changes the evidence could be either accidental or deliberate.

A

Evidence Dynamics -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data that has been processed and assembled so that it is relevant to an investigation.

A

Information -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A basic concept of forensic science, which states that “with contact between two items, there will be an exchange.” In other words, every contact leaves a trace.

A

Locard’s exchange principle -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data that is difficult to collect and analyze because it is encrypted, compressed, or in a proprietary format.

A

Obscured data -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A physical object that can be touched, held, or directly observed, such as a hard drive or removable media. Also: Any evidence that speaks for itself, without relying on anything else. An example is a log produced by an audit function.

A

Real evidence -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A court order that allows law enforcement personnel to collect equipment or data from that equipment. Search warrants are typically used by law enforcement officers.

A

Search warrant -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A court order than requires the person or organization that owns the equipment to release it for analysis. These are typically used in civil actions or court proceedings.

A

Subpoena -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Information that is used to support or interpret real or documentary evidence.

A

Testimonial evidence –

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Permission from a computer or equipment owner to search and/or seize equipment as part of an investigation

A

Voluntary surrender-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly