Udemy Test 1 Flashcards
The GUID is how many bits?
128 bits
This Federal statute covers child pornography.
18 USC 2252A
Which Windows version boots in either UEFI-GPT or BIOS-MBR?
Win 10
nnnn represents
The Sequential number of exhibits by the investigator
Sandra needs to see details about GPT partition tables in Mac OS. Which tool should she use?
Disk Utility
This is a network sniffer that can support several hundred network protocols.
Capsa
John is a forensic investigator working on a case for a WHC hospital. John finds a USB drive sitting behind an access control door in the server room. The hospital provides John access to retrieve the device. John knows that the USB represents:
Non-Volatile Data
Sara is an Assistant U.S. Attorney. She knows that this rule covers the general admissibility of relevant evidence.
Rule 402
In UEFI SEC, this is initialized.
Code is initialized
A Digital Forensic Investigator investigates this type of crime (choose the best answer).
Digital Crime
This is the smallest physical storage unit on the hard disk platter.
Sector
The zz in exhibit numbering stands for:
The squence number for parts of the same exhibit
Shamika is the VP of Technology at XYZ, Inc. She suspects that her newest employee, David, may be using his work computer to look at child pornography. What type of investigation(s) should be started?
Criminal and Administrative
The zz in exhibit numbering stands for:
The sequence number for parts of the same exhibit
Sectors are how many bytes long.
512
This is the smallest physical storage unit on the hard disk platter.
Sector
This is a tool for Mac that can be used to recover files from crashed or virus corrupted hard drives.
File Savage
This command can be used to obtain details about partitions.
Get-PartitionTable
Sectors are how many bytes long.
512 bytes
This is wasted area of the disk cluster, lying between the end of the file and end of the cluster.
Slack Space
All of these are a part of the Pre-investigation phase EXCEPT:
Acquiring the Evidence
This person provides legal advice about the investigation and any potential legal issues in the forensic investigation process.
Attorny
What does ETI stand for?
Enterprise Theory of Investigation
UTC stands for:
Coordinated Universal Time