Digital Evidence Collection and Preservation Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Evidence Collection and Preservation flashcards as text
Which type of acquisition is performed when a forensic examiner cannot shut down the target system without risking data loss?
Answer: Live acquisition
A live acquisition is performed on a running system to capture volatile data such as RAM contents, active network connections, and running processes that would be lost on shutdown.
In digital forensics, 'data carving' refers to:
Answer: Recovering files from unallocated space based on file signatures without file system metadata
Data carving reconstructs files from raw storage by identifying file headers and footers (magic bytes) without relying on file system structures, useful for recovering deleted files.
A forensic examiner collecting evidence from a corporate network should obtain which document before beginning the investigation to ensure legal authority?
Answer: Written authorization or consent from an authorized representative or a court order
Written authorization from an authorized party or a court order establishes the legal basis for the search and ensures evidence is admissible.
Which Windows log records successful and failed logon events and is critical for user activity analysis?
Answer: Security Event Log
The Security Event Log records authentication events including successful logons (Event ID 4624) and failed logon attempts (Event ID 4625).
When analyzing a smartphone using a logical acquisition, what is a key limitation compared to a physical acquisition?
Answer: Logical acquisition may miss deleted data and data outside the file system's view
Logical acquisition interfaces with the device's operating system APIs and only retrieves data the OS exposes, missing deleted records and data in unallocated storage that physical acquisition can recover.
What is the primary purpose of creating a forensic image (bit-for-bit copy) rather than a file-by-file copy?
Answer: To capture all data including deleted files, slack space, and unallocated areas
A forensic (bit-for-bit) image captures every sector of the storage media including unallocated space, slack space, and deleted data that a file-by-file copy would miss.
Which anti-forensics technique involves embedding hidden data within an image file without visibly altering the image?
Answer: Steganography
Steganography hides data within another file (such as an image) by subtly altering bits in ways not visible to the human eye, making detection difficult.