โ† All ACFE Flashcard Decks

Digital Forensics and Evidence Flashcards

7 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensics and Evidence flashcards as text
  1. Which standard framework governs the admissibility of scientific or technical expert testimony in US federal courts, relevant to digital forensics experts?

    Answer: Daubert standard

    The Daubert standard (from Daubert v. Merrell Dow Pharmaceuticals) requires judges to evaluate whether expert methodology is scientifically valid and reliably applied.

  2. A fraud examiner is investigating cryptocurrency transactions. What tool or resource is most useful for tracing Bitcoin wallet-to-wallet transfers?

    Answer: Public blockchain explorers like blockchain.com combined with chain analysis software

    Bitcoin's public blockchain records all transactions permanently; blockchain explorers and chain analysis tools (e.g., Chainalysis) trace fund flows between pseudonymous wallets.

  3. What does 'order of volatility' dictate in a digital forensics investigation?

    Answer: The priority order for collecting evidence, from most to least transient

    Order of volatility (per RFC 3227) guides examiners to collect most volatile data first (RAM, CPU cache) before collecting less volatile data (hard drives, backups).

  4. During a fraud investigation, an examiner discovers a suspect used TOR (The Onion Router). What limitation does TOR use present for investigators?

    Answer: TOR encrypts and routes traffic through multiple relays, masking the user's true IP address

    TOR anonymizes internet traffic by routing it through a series of encrypted relay nodes, making it extremely difficult to trace the originating IP address.

  5. What is 'data carving' in the context of digital forensics?

    Answer: Recovering files from unallocated space based on file signatures without relying on file system metadata

    Data carving identifies file headers and footers (magic bytes) in raw storage to reconstruct files even when directory entries have been deleted.

  6. An employee suspected of embezzlement used a personal Gmail account on a corporate laptop. Which artifact on the laptop is most likely to contain evidence of those webmail sessions?

    Answer: Browser cache, cookies, and IndexedDB/Local Storage files

    Web browsers cache page content, store authentication cookies, and maintain local databases that can contain session tokens, message fragments, and attachment filenames from webmail use.

  7. Under the Federal Rules of Evidence, electronically stored information (ESI) is generally treated as which type of evidence?

    Answer: Documentary evidence subject to authentication and best evidence requirements

    ESI is treated as documentary evidence under FRE 901 (authentication) and FRE 1001-1008 (best evidence rule), requiring the proponent to show it is what it purports to be.

Digital Forensics and Evidence Flashcards โ€” ACFE Study Cards with Answers