Digital Forensic Procedure Flashcards

(12 cards)

1
Q

What are Digital Forensics?

A

Systematic process of investigating and analyzing digital devices and data to uncover evidence for legal purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the 1st phase of Digital Forensics - Identification do?

A

Focus on scene safety, prevention of evidence contamination, and scope determination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does the 2nd phase of Digital Forensics - Collection do?

A

Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Order of Volatility?

A

Dictates the sequence in which data sources should be collected and preserved based on their susceptibility to rapid changes during system operation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Order of Volitility?

A

■ Collect data from the system’s memory
■ Capture data from the system state
■ Collect data from storage devices
■ Capture network traffic and logs
■ Collect remotely stored or archived data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Chain of Custody

A

Documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment it is collected until it is presented in a court of law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Disk Imaging? (copying storage device)

A

Involves creating a bit-by-bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does File Carving do?

A

Focuses on extracting files and data fragments from storage media without relying on the file system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the 3rd phase of Digital Forensics - Analysis do?

A

Systematically scrutinizing data to uncover relevant information like, timestamps, user interactions, and signs of criminal activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the 4th phase of Digital Forensics - Reporting do?

A

Involves documenting the findings, processes, and methodologies used during a digital forensic investigation in a final report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Legal Hold?

A

Formal notification that instructs employees to preserve potentially relevant electronic data, documents and records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is an E-Discovery (Electronic Discovery)?

A

Process of identifying, collecting, and presenting electronically stored information for potential legal proceedings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly