Week 3 - Types of Evidence Flashcards

1
Q

What are common types of evidence?

A
System logs
Application logs/cache files/history
Metadata (system and application)
Digital artifacts (tell-tale signs from applications)
Temporary data (system and application)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are system logs?

A

They are the systems logs of events that happened on said system. They give an insight to what has happened on a system level. It can include information from system databases, and is commonly used to identify user logins and related activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are application logs?

A

They are the log of events and activities that have occured on an application. It is ued to find out what happened when using a certain application. An example is internet browsing history.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the two types of metadata?

A

System based

Application based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is system based metadata?

A

Data created by the system that details the info on file creation, modifications, file size, permissions, and owner etc. for each file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is application based metadata?

A

Data associated with specific applications files, that normally includes data on the author and last modified by user. An example is Microsoft word files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are digital application artifacts?

A

Residual files that are left after running applications that detail the usage of that application during that session.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Waht is temporary data?

A

These files are created during the execution of certain processes for the process to use and store temporary data needed for that execution. These files are ‘cleaned’ or deleted after the process has finished executing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a trace?

A

Data left behind during the use of digital devices that can give insight into the events that transpired. E.g. a log of a transaction, browser history. It can be used as digital evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly