Digital Forensics and Evidence Flashcards
7 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Forensics and Evidence flashcards as text
What is the primary purpose of a write blocker in digital forensics?
Answer: To prevent any data from being written to the evidence drive during acquisition
A write blocker prevents the forensic tool from altering the evidence drive by blocking all write commands while allowing read operations.
Which file system artifact is most useful for identifying when a file was deleted on a Windows NTFS volume?
Answer: The $Recycle.Bin folder and $I files
The $Recycle.Bin folder stores $I files (index files) that contain the original path and deletion timestamp for each deleted file.
In the context of email fraud investigations, what does 'email header analysis' primarily reveal?
Answer: The routing path and originating server of a message
Email headers contain 'Received' fields that trace the message's path through mail servers, helping identify the true originating IP address.
A fraud examiner recovers a suspect's smartphone. Which extraction method yields the most comprehensive data, including deleted records?
Answer: Physical extraction
Physical extraction creates a bit-for-bit image of the device's memory chip, allowing recovery of deleted data and unallocated space artifacts.
What does 'MAC times' refer to in digital forensics?
Answer: Modified, Accessed, and Created/Changed timestamps on files
MAC times (Modified, Accessed, Changed/Created) are file system metadata timestamps that help establish a timeline of file activity.
Which of the following best describes 'steganography' as it relates to fraud investigations?
Answer: Hiding data within innocuous files such as images or audio
Steganography conceals secret data within ordinary-looking files, which fraudsters may use to covertly transfer stolen information.
During a forensic investigation of cloud storage, which legal instrument is typically required to compel a US-based cloud provider to produce user data?
Answer: A search warrant or court order under the Stored Communications Act (SCA)
The Stored Communications Act governs law enforcement access to electronic communications stored by third-party providers, generally requiring a warrant or court order.