Udemy Test 1 Flashcards

1
Q

The GUID is how many bits?

A

128 bits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

This Federal statute covers child pornography.

A

18 USC 2252A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Windows version boots in either UEFI-GPT or BIOS-MBR?

A

Win 10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

nnnn represents

A

The Sequential number of exhibits by the investigator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Sandra needs to see details about GPT partition tables in Mac OS. Which tool should she use?

A

Disk Utility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

This is a network sniffer that can support several hundred network protocols.

A

Capsa

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

John is a forensic investigator working on a case for a WHC hospital. John finds a USB drive sitting behind an access control door in the server room. The hospital provides John access to retrieve the device. John knows that the USB represents:

A

Non-Volatile Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Sara is an Assistant U.S. Attorney. She knows that this rule covers the general admissibility of relevant evidence.

A

Rule 402

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In UEFI SEC, this is initialized.

A

Code is initialized

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A Digital Forensic Investigator investigates this type of crime (choose the best answer).

A

Digital Crime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This is the smallest physical storage unit on the hard disk platter.

A

Sector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The zz in exhibit numbering stands for:

A

The squence number for parts of the same exhibit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Shamika is the VP of Technology at XYZ, Inc. She suspects that her newest employee, David, may be using his work computer to look at child pornography. What type of investigation(s) should be started?

A

Criminal and Administrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The zz in exhibit numbering stands for:

A

The sequence number for parts of the same exhibit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Sectors are how many bytes long.

A

512

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

This is the smallest physical storage unit on the hard disk platter.

A

Sector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

This is a tool for Mac that can be used to recover files from crashed or virus corrupted hard drives.

A

File Savage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

This command can be used to obtain details about partitions.

A

Get-PartitionTable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Sectors are how many bytes long.

A

512 bytes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

This is wasted area of the disk cluster, lying between the end of the file and end of the cluster.

A

Slack Space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

All of these are a part of the Pre-investigation phase EXCEPT:

A

Acquiring the Evidence

22
Q

This person provides legal advice about the investigation and any potential legal issues in the forensic investigation process.

23
Q

What does ETI stand for?

A

Enterprise Theory of Investigation

24
Q

UTC stands for:

A

Coordinated Universal Time

25
A computer forensics lab should have windows all around the perimeter.
False
26
What is the Size of the MBR?
512 bytes
27
What is DiskDigger?
Tool used to recover files and offers a thumbnail preview
28
For a router, the investigator should:
Unplug the network cable from the router
29
Jennifer is studying for her CHFI exam and knows that the MBR is:
512 bytes
30
There are this many bits for storing Logical Block Addresses (LBAs) on the Master Boot Record (MBR).
32 bits
31
The MBR signature is always:
0x55AA
32
An internal investigation, undertaken by an organization, to determine if employees are following rules and/or policies is called.
Administrative
33
Disk Density is calculated with:
Track, Area, and Bit Density
34
This rule governs proceedings in the courts of the United States.
Rule 101
35
Keira is an investigator with the FBI that needs to recover lost files from a USB flash drive. Which tool can help her do this?
Disk Digger
36
The GUID has this number of hexadecimal digits, with groups separated by hyphens.
32
37
Tools involved in Hashing include all of the following EXCEPT:
SuperHasher
38
In exhibit numbering, the aaa is:
The initials of the individual seizing the equipment
39
All investigators keep track of the evidence path by using the:
Chain of Custody Document
40
Circular, metal disks mounted into the drive enclosure are called:
Platters
41
Tasha is looking for the UEFI phase that involves clearing UEFI from memory.
RT
42
The Master Boot Record (MBR) starts at this sector.
Sector 0
43
A warrantless seizure of digital evidence is used when:
The destruction of the evidence is imminent and there is cause to believe that the item being seized constitutes evidence of criminal activity
44
Rule 1003 covers:
admissibility of duplicates
45
What is Recover my Files?
a Tool used for file recovery
46
What is the size of the MBR Partition Table?
64 bytes
47
What is the size of the MBR Partition Table?
64 bytes
48
Rule 1002 Covers?
The Admissibility of original evidence
49
Rule 1001 covers?
Definitions
50
Rule 1004 Covers?
Other evidence admissibility