โ† All CCE Flashcard Decks

Digital Evidence Collection & Preservation Flashcards

7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Evidence Collection & Preservation flashcards as text
  1. Which of the following best describes the concept of 'write blocking' in digital forensics?

    Answer: Preventing any data from being written to the evidence drive during acquisition

    Write blockers prevent any write operations to the source evidence drive, ensuring the original data remains unaltered during forensic acquisition.

  2. A forensic examiner needs to collect volatile data from a live Windows system. What should be collected FIRST?

    Answer: Contents of the RAM

    RAM contents are the most volatile and will be lost immediately upon shutdown, so they must be captured before any other volatile data collection.

  3. What is the primary purpose of creating a forensic image rather than copying files individually?

    Answer: To capture all data including deleted files, slack space, and unallocated space

    A forensic image captures the entire bit-for-bit copy of the storage medium, preserving deleted files, slack space, and unallocated space that individual file copies would miss.

  4. During evidence collection, an examiner discovers the suspect's laptop has full disk encryption enabled and is currently powered on. What is the recommended action?

    Answer: Perform a live acquisition before shutting down

    When an encrypted device is powered on and unlocked, a live acquisition should be performed to capture the decrypted data before the device is shut down and encryption re-engages.

  5. What does the term 'chain of custody' refer to in digital forensics?

    Answer: The documented chronological history of who handled, collected, and transferred evidence

    Chain of custody is the chronological documentation showing the seizure, custody, control, transfer, and analysis of evidence, ensuring its integrity and admissibility.

  6. Which hashing algorithm is currently recommended by NIST for verifying the integrity of forensic images?

    Answer: SHA-256

    SHA-256 is the current NIST-recommended hashing algorithm as MD5 and SHA-1 have known collision vulnerabilities that could undermine evidence integrity verification.

  7. A first responder arrives at a scene where a desktop computer is running. Network cables are connected. What should be done regarding the network connection?

    Answer: Document the connection state before deciding whether to disconnect

    The examiner should document the current state of network connections before taking any action, as the decision to disconnect depends on case specifics and may need to be justified later.