Sett 2 Flashcards
Which is not a formal position in a forensics lab?
Investigator, manager, analyst, legal manager
Legal manager
What are the CERT standards for a forensic laboratory?
ASCLD (American Society of Crime Laboratory Directors) does the test and their process is based on ISO 17025:2005.
Which role develops and forces lab policies?
lab manager
What role is testifying the facts of data gathered?
Analyst
Which is not a service offered by a forensics lab?
Adversary emulation
Parking lot security and biometric authentication are what level security?
Lab level 4
Physical control, neither, or tech control?
Fencing
ballards
identity management
firewalls
security
training
procedures
Fencing, ballards phys
identity management, firewalls, security tech
training, procedures neutral
Cc television is what physical security control?
Preventative, detective, corrective, recovery, deterrent, or compensate
Detective
George needs a forensics package that is free to use and can examine images of hard drives. What should he use?
Autopsy
Ken is a lead investigator, he surveys a crime scene. What tool will not contaminate digital evidence?
Write Blocker
Company is closing, highly sensitive data is on their systems what sanitization method must be used?
Destroy
Which is not a santitization term?
Wipe
Maintained by SANS to help with forensic issues?
SIFT
What company does specification for data sanitization standards?
NIST (National Institute of Standards Technology)
Which org certifies free tools to examine images on a hard drive?
CFTT (The Computer Forensics Tool Testing) Handbook
Before you seize any evidence what must you have?
A warrant
As a member of her organization’s IS team, Larissa is performing a data forensic investigation involving 3 members of the corporate finance team. Before Larissa can seize any evidence from the suspects employee’s computer, she must have an active warrant? True or False
False
5th amendment is search and seizure? True or False
False/4th amendment is search and seizure
Going to a judge with a request to seize digital evidence the request must provide what?
Probable cause
Evidence may be seized without a warrant if people are in danger, these are called what?
Exigent circumstances