โ† All CCE Flashcard Decks

Digital Evidence Collection & Preservation Flashcards

7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Evidence Collection & Preservation flashcards as text
  1. What is 'chip-off' forensics and when is it typically employed?

    Answer: Physically removing flash memory chips from a device to read them directly with specialized equipment

    Chip-off forensics involves physically desoldering and removing flash memory chips (NAND/NOR) from a device to read their raw contents when software-based acquisition methods fail.

  2. Under the Federal Rules of Evidence (FRE), what must be established for digital evidence to be considered authentic?

    Answer: The proponent must produce evidence sufficient to support a finding that the item is what it is claimed to be

    Under FRE Rule 901, authentication requires sufficient evidence to support a finding that the digital evidence is what the proponent claims, typically demonstrated through hash verification and chain of custody.

  3. What is the purpose of the 'best evidence rule' (FRE Rule 1002) in digital forensics?

    Answer: It requires the original writing, recording, or photograph to prove its content, or a reliable duplicate

    The best evidence rule requires the original or a reliable duplicate (like a forensic image with verified hash) to prove the content of a recording, which is why forensic images are treated as equivalent to originals.

  4. An examiner receives a storage device that has been exposed to water. What is the recommended immediate action?

    Answer: Submerge the device in distilled water to prevent oxidation until a specialist can examine it

    Keeping a water-damaged storage device submerged in distilled water prevents oxidation and corrosion while it awaits specialist recovery, as air exposure causes rust that can destroy the device.

  5. What is a 'hash set' and how is it used in digital evidence collection?

    Answer: A database of known file hash values used to identify known good or known bad files

    A hash set is a database of pre-computed hash values (such as NSRL for known good files or CAID for child exploitation material) used to quickly identify or exclude files during forensic examination.

  6. During evidence collection at a business, the examiner discovers the primary suspect's workstation is connected to a RAID array. How should the RAID array be handled?

    Answer: Document the RAID configuration and controller settings before disassembly, then image individually

    RAID configuration details (type, stripe size, drive order) must be documented before disassembly because this information is needed to reconstruct the logical volume from individual drive images.

  7. What is the forensic significance of the Windows $LogFile artifact on an NTFS volume?

    Answer: It is the NTFS transaction log that records file system metadata changes, useful for timeline reconstruction

    The NTFS $LogFile is a transaction journal that records file system metadata operations, allowing forensic examiners to reconstruct recent file creation, deletion, and modification events even after MFT entries are overwritten.