Set 1 Flashcards
What is a forensics Lab?
Workspace to perform data extraction, analysis, and reporting, must be accredited such as with ISO/IEC 17025:2005
What is a Forensics Lab Manager responsible for?
for the overall operation of the lab, ensures analysts have what they need, handles staffing, ensures staff receive appropriate training.
What does a Forensics Analyst do?
Performs scientific analysis of collected digital evidence collected from a variety of sources.
Define a Forensics investigator.
Focuses on collection and retrieval of digital evidence. Similiar to Forensics Analyst.
What does ASCLD stand for?
American Society Crimes Laboratory Directors
What does ASCLD/Labs group do?
They conduct forensics lab certification.
What do the security mechanisms Preventive, Detective, & Corrective mean?
Preventive - Prevents a security incident from happening
Detective - Discovers if a security event is in progress or has already occurred
Corrective - Aimed at fixing the root cause of the vulnerability that gave rise to the incident
What do the security mechanisms Recovery, Deterrent, and Compensating mean?
Recovery - Restores the computing environment back to a “good known state”
Deterrent - Keeps an event from happening by creating an obstacle for the attacker
Compensating - A control inserted to compensate for lack of a permanent control
What are two principles of physical security?
Ensure the physical security of the lab.
Ensure the physical security of the evidence within the lab.
Why would you want two separate tables in a forensics lab?
One with two forensics workstations
One with one or two plain workstations for results validation.
What is 5WH?
Questions used for problem solving.
They consist of who, what, when, where, why, how.
Define computer forensics
The collection and preservation of evidence
What is used to manipulate mace attributes and how?
Time stomp, modifies the timestamp of a file
Who was a Nobel Prize winner and discovered blood types?
Karl Landsteiner
What is Locard’s exchange principle?
A criminal will bring something and leave something that can be used as forensic evidence.
How many set of criminal laws exist in the united states?
51
Unreasonable search and seizure is what bill?
The 4th
Security control that happens in the event of a crime?
Detection
what is considered investigation for business use?
Corporate
Data forensic analysis is responsible for what?
Collecting and preserving criminal evidence
Which are considered two great laws of forensics?
Never work with the original, preserve the state it was found in.
What determined the murderer of Robert eidman?
touch DNA from the lining of Eidman’s pocket
People vs holcolm is a criminal case? true or false
True