ETC Digital & Electronic Evidence Flashcards
6 cards from real ETC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 ETC Digital & Electronic Evidence flashcards as text
What is the first step an evidence technician should take upon encountering a powered-on computer at a crime scene?
Answer: Photograph the screen, document its state, and consult with a digital forensics specialist before touching it
Documenting the screen's current state before any action preserves volatile data and allows a digital forensics specialist to advise on whether to acquire live data or power down.
Why is it important to place a cell phone in a Faraday bag or airplane mode immediately upon seizure?
Answer: To prevent remote wiping, incoming data, or location updates that could alter evidence
Isolating the phone from wireless signals prevents remote wipe commands, new incoming messages, or GPS updates from altering the data on the device.
What is a write blocker and why is it used in digital evidence processing?
Answer: A hardware or software device that prevents any writes to a storage medium, ensuring the original is not altered during imaging
A write blocker allows forensic tools to read data from a storage device without making any changes, preserving the original evidence in its unaltered state.
Which hashing algorithm is most commonly used to verify the integrity of a digital evidence image?
Answer: MD5 or SHA-256
MD5 and SHA-256 cryptographic hash values are computed before and after imaging; matching hashes confirm the copy is identical to the original.
When seizing a smartphone as digital evidence, which data may be lost if the battery dies before forensic acquisition?
Answer: Volatile data in RAM such as active app states and temporary files
RAM is volatile memory that is erased when power is lost; active app states, decryption keys, and temporary data that could be forensically valuable are lost when the battery dies.
What documentation is required when seizing digital devices as evidence?
Answer: Photographs of the device, its connections, and screen; a complete inventory of all seized items with make, model, and serial number
Proper digital device seizure requires photographs showing the device's state and connections, plus a detailed inventory capturing make, model, serial number, and any visible damage.