โ† All ALISON Flashcard Decks

Digital Forensics & Cybercrime Investigation Flashcards

6 cards from real ALISON practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Digital Forensics & Cybercrime Investigation flashcards as text
  1. What is 'anti-forensics' and what challenge does it present to investigators?

    Answer: Techniques used by attackers to destroy, hide, or alter digital evidence to impede investigations

    Anti-forensics includes wiping tools, timestamp manipulation, and encryption to make evidence collection harder or impossible for investigators.

  2. What is the role of a 'write blocker' in digital forensics?

    Answer: To prevent any writes to the evidence drive during imaging, preserving its original state

    A write blocker is a hardware or software device that allows read-only access to storage media, preventing accidental or deliberate modification of evidence.

  3. What is 'network forensics' focused on?

    Answer: Capturing and analyzing network traffic to reconstruct events and identify attackers

    Network forensics involves monitoring and analyzing network packets, flows, and logs to reconstruct attack timelines and identify malicious activity.

  4. Which concept in cybercrime investigation refers to determining what happened, when, who did it, and how during an incident?

    Answer: Forensic timeline reconstruction

    Forensic timeline reconstruction correlates timestamps across logs, file system metadata, and artifacts to create a chronological narrative of an incident.

  5. What US law governs the interception of electronic communications and is relevant to digital forensics investigations?

    Answer: Electronic Communications Privacy Act (ECPA)

    The ECPA sets legal standards for accessing stored electronic communications and monitoring digital transmissions, directly governing how forensic evidence is collected.

  6. What is a 'memory dump' and why is it important in malware forensics?

    Answer: A capture of the contents of RAM at a point in time, revealing running processes and loaded malware

    Memory dumps capture volatile RAM contents including running processes, network connections, decrypted data, and in-memory malware that leaves no disk artifacts.