Quiz 3 Flashcards
The variety of tools and software makes digital forensics easily affordable by agencies to train and equip its own examiners. True or False?
False
Advantages, including cost savings, greater access to more resources (tools and storage), access to diverse expertise and reduction of unnecessary duplication of resources can be achieved through
virtual labs.
Connecting an evidence drive brought in for examination to an internal forensic network
the ability to log individual access.
A well documented system of protocols used to assure the accuracy and reliability of analytical results is the definition of
quality assurance.
An open proficiency test is conducted by an agency independent of the agency being tested; whereas a blind proficiency test is one where the analysts and technical support personnel are not aware they are being tested. True or False?
False
Each and every tool must be validated before it’s used on an actual case. A validation process demonstrates (check all that apply)
the tool is working properly.
the tool is reliable.
the tool yields accurate results.
Accreditation refers to the laboratory and certification pertains to the individual examiners. True or False?
True
Most labs will have a variety of tools at their disposal for the following reasons (choose all that apply)
to give them the broad capability they need.
no one tool does everything.
to handle a wide array of technology requiring analysis
Accreditation is an endorsement of a crime lab’s policies and procedures. Laboratory accreditation is highly desirable but not mandatory. True or False?
True
In general, what would a lightweight forensics workstation consist of?
A laptop computer built into a carrying case with a small selection of peripheral options
Passwords are typically stored as one-way _____________ rather than in plaintext.
hashes
What hex value is the standard indicator for jpeg graphics files?
FF D8
The ProDiscover utility makes use of the proprietary _______________ file format.
.eve
What program serves as the GUI front end for accessing Sleuth Kit’s tools?
Autopsy
In what mode do most write-blockers run?
Shell mode