Digital Forensics & Cybercrime Investigation Flashcards
6 cards from real ALISON practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Digital Forensics & Cybercrime Investigation flashcards as text
What is the primary purpose of maintaining a 'chain of custody' in digital forensics?
Answer: To ensure digital evidence remains admissible and unaltered throughout an investigation
Chain of custody documents every person who handled evidence and every action taken, ensuring its integrity and legal admissibility in court.
Which principle in digital forensics states that any contact between two items leaves a trace?
Answer: Locard's Exchange Principle
Locard's Exchange Principle states that every contact leaves a trace, which in digital forensics means system interactions leave artifacts like logs and metadata.
What is the correct order of volatility in digital evidence collection?
Answer: CPU registers → RAM → Network → Disk
Evidence should be collected from most volatile (CPU registers, cache) to least volatile (disk) to preserve the most transient data first.
What is a 'forensic image' in digital forensics?
Answer: A bit-for-bit copy of a storage device including unallocated space
A forensic image is an exact sector-by-sector copy of a storage medium that captures all data including deleted files and unallocated space.
What tool is commonly used on Linux/Unix systems to create a forensic bit-stream image of a drive?
Answer: dd
The dd command creates a raw bit-stream copy of a device, making it one of the most fundamental forensic imaging tools on Unix-like systems.
Which hashing algorithm is most commonly used to verify the integrity of forensic disk images?
Answer: MD5 or SHA-1/SHA-256
MD5 and SHA-256 hash values are calculated before and after imaging to verify that the forensic copy is identical to the original.