ETC ETC Digital & Electronic Evidence 1 — Questions and Answers
Question 1: What is the first step an evidence technician should take upon encountering a powered-on computer at a crime scene?
- Photograph the screen, document its state, and consult with a digital forensics specialist before touching it (Correct answer)
- Immediately shut it down by pulling the power cord
- Restart the computer to capture a fresh state
- Log into the system to check recent files
Correct answer: Photograph the screen, document its state, and consult with a digital forensics specialist before touching it
Documenting the screen's current state before any action preserves volatile data and allows a digital forensics specialist to advise on whether to acquire live data or power down.
Question 2: Why is it important to place a cell phone in a Faraday bag or airplane mode immediately upon seizure?
- To prevent remote wiping, incoming data, or location updates that could alter evidence (Correct answer)
- To charge the battery before lab analysis
- To trigger the phone's backup feature
- To avoid static electricity damage during transport
Correct answer: To prevent remote wiping, incoming data, or location updates that could alter evidence
Isolating the phone from wireless signals prevents remote wipe commands, new incoming messages, or GPS updates from altering the data on the device.
Question 3: What is a write blocker and why is it used in digital evidence processing?
- A hardware or software device that prevents any writes to a storage medium, ensuring the original is not altered during imaging (Correct answer)
- A software tool that encrypts digital evidence files
- A label applied to evidence bags to prevent re-opening
- A physical lock placed on evidence room doors
Correct answer: A hardware or software device that prevents any writes to a storage medium, ensuring the original is not altered during imaging
A write blocker allows forensic tools to read data from a storage device without making any changes, preserving the original evidence in its unaltered state.
Question 4: Which hashing algorithm is most commonly used to verify the integrity of a digital evidence image?
- MD5 or SHA-256 (Correct answer)
- CRC32 only
- Base64 encoding
- AES-256 encryption
Correct answer: MD5 or SHA-256
MD5 and SHA-256 cryptographic hash values are computed before and after imaging; matching hashes confirm the copy is identical to the original.
Question 5: When seizing a smartphone as digital evidence, which data may be lost if the battery dies before forensic acquisition?
- Volatile data in RAM such as active app states and temporary files (Correct answer)
- Photos stored on an SD card
- Contacts saved to the SIM card
- Previously downloaded files in internal storage
Correct answer: Volatile data in RAM such as active app states and temporary files
RAM is volatile memory that is erased when power is lost; active app states, decryption keys, and temporary data that could be forensically valuable are lost when the battery dies.
Question 6: What documentation is required when seizing digital devices as evidence?
- Photographs of the device, its connections, and screen; a complete inventory of all seized items with make, model, and serial number (Correct answer)
- Only a property receipt with the device description
- A written summary of the suspect's statements about the device
- Video of the seizure and a signed consent form only
Correct answer: Photographs of the device, its connections, and screen; a complete inventory of all seized items with make, model, and serial number
Proper digital device seizure requires photographs showing the device's state and connections, plus a detailed inventory capturing make, model, serial number, and any visible damage.
What is the first step an evidence technician should take upon encountering a powered-on computer at a crime scene?