Targeted Flashcards
What allows for a lawful search to be conducted without a warrant or probable cause?
Consent of person with authority
When is warrantless seizure of evidence justified?
When destruction of evidence is imminent and there is probable cause that the seized item is evidence of criminal activity.
When can an investigator collect evidence without formal consent?
When properly worded banners are displayed on a computer screen.
What is a web app threat in which the application unintentionally reveals sensitive information to an unauthorized user?
Information Leakage
What type of information can be found in a common metadata field for a file?
Network name
Which registry key can be analyzed to retrieve folder information?
BagMRU
Which registry key tracks files that have been opened or saved within a Windows shell dialog box?
OpenSaveMRU
Which registry key may shed light on a user’s activity in a system and can indicate execution of a program or script on a device?
RunMRU
Which file format is being viewed if the first hex characters are 42 4D?
BMP
Which file format is being viewed if the first hex characters are 47 49 46 38?
GIF
Which file format is being viewed if the first hex characters are 89 50 4e 47?
PNG
Which file format is being viewed if the first hex characters are ff d8 ff?
JPEG
Which file format is being viewed if the first hex characters are 25 50 44 46?
Which file format is being viewed if the first hex characters are d0 cf 11 e0 a1 b1 1a e1?
XLS, DOC, or PPT
Which file format is being viewed if the first hex characters are 50 4b 03 04 14 00 06 00?
XLSX, DOCX, or PPTX
Which file format is being viewed if the first hex characters are 4e 42 2a 00?
JNT
Which file format is being viewed if the first hex characters are 50 4b 03 04?
ZIP
Which file format is being viewed if the first hex characters are 52 61 72 21 1a 07?
RAR
Which file format is being viewed if the first hex characters are 30 26 b2 75 8e 66 cf 11?
WMV
Which file format is being viewed if the first hex characters are 52 49 46 46?
AVI
Which file format is being viewed if the first hex characters are 49 44 33 03?
MP3
Which file format is being viewed if the first hex characters are 49 20 49?
TIF
Which software tool is designed strictly for maintaining the integrity of evidence during data acquisition?
SAFE Block
What is the difference between the NIST SP 800-88 recommended types of sanitization, clear, purge, and destroy?
clear: sanitizes media but does not guarantee infeasible recover. allows media reuse.
purge: sanitizes media and guarantees infeasible recovery. allows media reuse.
destroy: destroys media and guarantees infeasible recovery. media not reusable.