Digital Forensic Principles & Methodologies Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital Forensic Principles & Methodologies flashcards as text
In a corporate investigation, an examiner is asked to collect evidence from an employee's cloud storage account. What is the most critical first step?
Answer: Obtain proper legal authority such as a warrant, consent, or court order before accessing the account
Accessing cloud accounts without proper legal authority may violate the Stored Communications Act and other laws, rendering the evidence inadmissible.
What does the Master Boot Record (MBR) contain that is forensically significant?
Answer: Partition table, boot code, and disk signature
The MBR contains the bootstrap code, the partition table defining disk layout, and a unique disk signature—all relevant to understanding disk structure.
An examiner is analyzing Windows Volume Shadow Copies (VSS). What forensic value do they provide?
Answer: They provide point-in-time snapshots of the file system allowing recovery of previous file versions
Volume Shadow Copies are point-in-time snapshots of the file system that can contain previous versions of files, deleted files, and earlier registry states.
What is the difference between a 'forensic duplicate' and a 'forensic image'?
Answer: A forensic image is a bit-for-bit copy stored in a container format (e.g., E01); a forensic duplicate is a physical sector-by-sector clone to another drive
A forensic image stores the bit-for-bit copy in a container file (like E01 or DD), while a forensic duplicate is a physical sector-by-sector clone onto another physical drive.
Which artifact in Windows tracks recently accessed files and folders and can provide evidence of user activity even after files are deleted?
Answer: Windows Jump Lists and LNK files
Jump Lists and LNK (shortcut) files record recently and frequently accessed files, applications, and destinations, persisting even after original files are deleted.
An examiner needs to verify the integrity of a forensic image file after transferring it to another system. Which approach is correct?
Answer: Recompute the hash of the image file and compare it to the original acquisition hash
Recomputing and comparing hash values (MD5, SHA-1, or SHA-256) after transfer is the definitive method for verifying that the image was not corrupted or altered.
Under what circumstance can a forensic examiner legally bypass obtaining a search warrant to seize and examine digital evidence in the United States?
Answer: Under valid consent from an authorized user, exigent circumstances, or a recognized exception to the warrant requirement
Warrantless searches are permissible under recognized Fourth Amendment exceptions including voluntary consent, exigent circumstances, plain view, and border searches.