Digital Forensic Principles & Methodologies Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Forensic Principles & Methodologies flashcards as text
Which legal doctrine requires that digital evidence be obtained through lawful means to be admissible in court?
Answer: Fruit of the poisonous tree
The 'fruit of the poisonous tree' doctrine excludes evidence derived from an illegal search or seizure.
During a forensic investigation, an examiner discovers a file with a .jpg extension but the file header shows it is actually a ZIP archive. What technique was used?
Answer: File signature spoofing
File signature spoofing involves changing a file's extension to disguise its true type, which can be detected by comparing the header magic bytes to the extension.
What is the primary purpose of a write blocker in digital forensics?
Answer: To prevent modification of the source evidence drive
A write blocker prevents any write commands from reaching the evidence drive, ensuring the original data is not altered during acquisition.
Which of the following best describes 'slack space' in digital forensics?
Answer: Space between the end of a file and the end of its last cluster
Slack space is the unused space between the end of a file's data and the end of the last cluster allocated to that file.
An investigator must examine a live running system before powering it down. What type of data should be collected first due to its volatile nature?
Answer: RAM contents and running processes
RAM contents, running processes, and network connections are volatile and lost when the system powers down, so they must be captured first.
What does the term 'metadata' refer to in the context of digital forensics?
Answer: Data that describes or provides information about other data
Metadata is data that provides information about other data, such as file creation dates, author information, and GPS coordinates in photos.
Which standard model outlines the phases of a digital forensic investigation including identification, preservation, collection, examination, analysis, and presentation?
Answer: NIST SP 800-86
NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response) outlines a forensic process model with identification, collection, examination, and analysis phases.