← All FBI Flashcard Decks

FBI Cybercrime and Digital Forensics Flashcards

6 cards from real FBI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 FBI Cybercrime and Digital Forensics flashcards as text
  1. What is the FBI's Internet Crime Complaint Center (IC3)?

    Answer: A public-facing portal where citizens and businesses report internet-based crimes to the FBI

    IC3 (www.ic3.gov) is the FBI's public complaint portal for internet crime, receiving and analyzing millions of complaints annually and referring cases to appropriate law enforcement.

  2. What chain-of-custody step is most critical when an FBI agent seizes a live computer system running as evidence?

    Answer: Documenting the running state, capturing volatile memory (RAM) before imaging, then powering off

    With live systems, volatile data in RAM (encryption keys, running processes, network connections) must be captured first because it is lost when power is removed, then a forensic image of storage drives is made.

  3. What federal law governs FBI access to stored email content held by providers like Google or Microsoft?

    Answer: The Electronic Communications Privacy Act (ECPA) / Stored Communications Act

    The Stored Communications Act (18 U.S.C. §§ 2701-2712), part of ECPA, governs government access to stored electronic communications and requires different legal processes depending on content age and type.

  4. What is 'spear phishing' as used in FBI cyber case classifications?

    Answer: A highly targeted phishing attack customized to a specific individual or organization to gain access to systems or credentials

    Spear phishing uses personalized, research-based deception targeting specific individuals — often executives or employees with system access — to steal credentials or deploy malware.

  5. What is the purpose of a forensic 'write blocker' in an FBI digital evidence examination?

    Answer: To ensure that connecting a storage device for analysis does not alter or write any data to the original evidence

    A write blocker is a hardware or software device that allows data to be read from a storage medium for forensic imaging while preventing any data from being written back, preserving evidence integrity.

  6. Under U.S. law, cryptocurrency transactions on a public blockchain are considered what from an FBI investigative standpoint?

    Answer: Pseudonymous — traceable through blockchain analysis to identify transacting parties

    Public blockchains are permanent, public ledgers; while addresses are pseudonymous, blockchain analytics tools allow the FBI to trace transactions and link addresses to real identities through exchange records.