Week 5 Flashcards
Data of evidentiary value is commonly referred to as what?
Artifacts
What is the opposite of dead box analysis?
Live forensics
What is the name of the device which prohibits the computer from writing data during live forensics?
A write blocker
What is the difference between a physical disk image and a logical disk image?
Physical: bit-by-bit copy
Logical: copy of partitions as seen by OS
What are examples of volatile data that can be collected during live analysis?
Current network connections, current user, analyse possible encryption software
Why do we need to account for all data on a hard drive?
To establish if there are hidden partitions
Why is it important to examine time zone settings on a device?
To establish accurate timelines in criminal investigations