Communication & Documentation Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Communication & Documentation flashcards as text
When documenting the use of FTK Imager for evidence acquisition, which output should be recorded in the case notes?
Answer: Source evidence details, hash values, acquisition time, and tool version
Complete acquisition documentation includes the source drive details, MD5/SHA1 hash values, timestamps, and the exact version of FTK Imager used.
An examiner is asked by media to comment on an ongoing investigation. The appropriate response is to:
Answer: Decline and direct inquiries to the agency or attorney handling the case
Forensic examiners must not make public statements about active cases; all media communications should be directed to the responsible agency or legal counsel.
Which practice best ensures consistency in forensic documentation across multiple examiners within an organization?
Answer: Adopting standardized report templates and documentation procedures
Standardized templates and procedures ensure that all reports meet the same quality and completeness standards regardless of which examiner authored them.
What does 'chain of custody' documentation specifically protect against?
Answer: Allegations that evidence was tampered with or mishandled
Chain of custody documentation creates an auditable record of who handled evidence and when, protecting against claims of tampering or contamination.
When writing the findings section of a forensic report, an examiner should avoid:
Answer: Making statements that exceed what the data directly supports
Examiners must limit findings to what the evidence actually demonstrates and avoid overstating conclusions or implying certainty that the data does not support.
In AccessData FTK, 'bookmarking' evidence items primarily serves to:
Answer: Flag and organize relevant items for inclusion in reports and presentation
Bookmarks in FTK allow examiners to tag and organize significant evidence items for easy retrieval and inclusion in the final case report.
Which element distinguishes a forensic report from a standard IT incident report?
Answer: Evidentiary standards, chain of custody references, and legal admissibility considerations
Forensic reports are governed by evidentiary standards and must address admissibility, chain of custody, and methodology in ways standard IT reports do not require.