M12: Forensics Flashcards

1
Q

What is the first phase in the forensic process?

A

Collection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the collection phase involve?

A
  • Identifying
  • Labeling
  • Recording
  • Acquiring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is timely data collection important?

A

To prevent loss of dynamic data like network connections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the second phase in the forensic process?

A

Examination.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What happens during the examination phase?

A

Processing collected data to extract relevant information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the third phase in the forensic process?

A

Analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the goal of the analysis phase?

A

To derive useful information from the examined data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the final phase in the forensic process?

A

Reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What should be included in the reporting phase?

A
  • Actions taken
  • Tools used
  • Recommendations.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why is preserving data integrity important in forensics?

A

To ensure the data remains unchanged and reliable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the basics of file storage media?

A

Devices like hard drives, CDs, and USB drives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a filesystem?

A

A method for storing and organizing files on media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why is file integrity important?

A

To ensure files have not been altered or corrupted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are file modification… access… and creation times?

A

Metadata that shows when a file was last changed, accessed, or created.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of copying files from media?

A

To create a backup or transfer data without altering the original.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a forensic toolkit?

A

A set of tools used to examine and analyze data files.

17
Q

How can data files be located?

A

By searching the filesystem or using forensic tools.

18
Q

What is data extraction?

A

The process of retrieving specific information from data files.

19
Q

Why is it important to use legally justifiable methods in forensics?

A

To ensure the evidence is admissible in court.

20
Q

What should be done if technical issues arise during data collection?

A

Follow established procedures to resolve them.

21
Q

What is the significance of file headers?

A

They contain important information about the file type and structure.

22
Q

How can file integrity be verified?

A

By comparing file hashes before and after copying.

23
Q

What are some common types of media used for data storage?

A

Hard drives, SSDs, CDs, DVDs, and USB drives.

24
Q

What is the role of file metadata in forensics?

A

It provides details about the file’s history and usage.

25
Q

How can forensic tools help in data recovery?

A

By retrieving lost or deleted files from storage media.

26
Q

What is the importance of maintaining a chain of custody?

A

To document who handled the evidence and when.

27
Q

What are some challenges in examining data files?

A

Issues like
* Encryption
* File corruption
* Large data volumes.

28
Q

How can data files be securely stored?

A

Using encrypted storage and access controls.

29
Q

What is the purpose of analyzing data files?

A

To find relevant information that supports an investigation.

30
Q

Why is it important to document the forensic process?

A

To provide a clear record of actions taken and findings.