AccessData Investigator Digital Forensics & Evidence Analysis Flashcards
6 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 AccessData Investigator Digital Forensics & Evidence Analysis flashcards as text
What is the primary goal of digital forensics?
Answer: To collect, preserve, and analyze digital evidence
Digital forensics involves collecting, preserving, and analyzing electronic evidence to support legal and investigative processes.
Which type of data is considered volatile and should be collected first during an investigation?
Answer: RAM and system memory
Volatile data, such as RAM contents, is temporary and can be lost when a device is powered off, making it a priority for collection.
What is the purpose of a write blocker in digital forensics?
Answer: To prevent modifications to evidence
A write blocker prevents any modifications to a digital device during analysis, ensuring that the original evidence remains intact and admissible in court.
Which forensic technique is used to recover deleted files?
Answer: File carving
File carving allows forensic investigators to recover deleted files by identifying file structures even when metadata has been removed.
What is the importance of chain of custody in digital forensics?
Answer: To track and document evidence handling
Maintaining a chain of custody ensures that digital evidence is documented and handled properly, preserving its integrity for legal proceedings.
Which tool is commonly used for forensic analysis of digital devices?
Answer: Autopsy
Autopsy is a widely used forensic tool for analyzing digital evidence, allowing investigators to examine file systems, recover data, and analyze user activity.