IS4670 CHAPTER 4 Forensics Methods and Labs Flashcards
1
Q
- To be ________, data must be complete and materially unaltered.
A
Forensically sound
2
Q
2. Which of the following governs whether, when, how, and why proof of a legal case can be placed before a judge or jury? A. Forensic soundness B. Computer-generated evidence C. Rules of evidence D. Human-generated evidence
A
Rules of evidence
3
Q
- A framework for digital investigation to ensure forensic soundness must have six phases.
A. True
B. False
A
False
4
Q
- A ________ can help justify the acquisition of newer and better resources to investigate computer forensics cases.
A
Business case
5
Q
5. Which of the following provides guidelines for managing a forensics lab and acquiring crime and forensics lab certification? A. NIST B. ASCLD C. FRE D. DFRWS
A
ASCLD
6
Q
- Only very large computer forensics labs need a lab manager.
A. True
B. False
A
FALSE
7
Q
7. Which of the following costs should a computer forensics lab budget include? (Select three.) A. Facility costs B. Hardware costs C. Software costs D. Law enforcement costs E. Cleaning costs
A
Facility costs
Hardware costs
Software costs
8
Q
8. Staff members in a computer forensics lab should have sufficient training to perform their tasks. Necessary skill sets include all except which of the following? A. Hardware knowledge B. Software knowledge C. Background as an attorney D. Deductive reasoning
A
Background as an attorney
9
Q
9. A forensic workstation should be set up in a secure room in a forensics lab. What are some important features for such a room? (Select three.) A. Large room B. Floor-to-ceiling walls C. Locking doors D. Fireproof doors E. Secure containers that lock
A
Floor-to-ceiling walls
Locking doors
Secure containers that lock
10
Q
- Every organization should strive to make its lab a TEMPEST-qualified lab facility.
A. True
B. False
A
True
11
Q
- Evidence storage containers should store only current evidence. Evidence for closed cases should be moved to a secure offsite facility.
A. True
B. False
A
True
12
Q
12. Which of the following logs should a computer forensics lab keep? (Select two.) A. Computer use log B. Lab visitors’ log C. Evidence container log D. Criminal log
A
Evidence container log
Visitors log
13
Q
- A forensics lab work area requires approximately ________ square feet.
A
150
14
Q
14. Which of the following does a forensics lab not need to stock? A. Workstations B. Operating systems C. Legal manuals D. Hard drives
A
Legal manuals
15
Q
- As a general precaution, it is a good idea to back up a workstation once a month.
A. True
B. False
A
False