- __________ is a branch of digital forensics dealing with identifying, managing, and preserving digital information that is subject to legal hold. E-discovery
- A physical hard disk drive will persist data longer than a solid state drive. True
- A technician must ensure that a forensic copy is ___. a bit-by-bit copy of the drive
- Anyone who handles evidence in an investigation should __ Be recorded on the Chain of Custody logs
- Both forensics and e-discovery are secondary processes from a business perspective True
- Business records, printouts, and manuals are which type of evidence? Documentary evidence
- Clusters that are marked by the operating system as usable when needed are referred to as __________. free space
- Clusters that are marked by the operating system as usable when needed are referred to as ____ Free space
- Ensuring your computer does not inadvertently make changes to a target machine’s media, investigators should install a write blocker to the media
- Evidence offered by a witness that is not based on the personal knowledge of the witness, but is being offered to prove the truth of the matter asserted, falls under which rule of evidence? Hearsay rule
- Evidence offered by a witness that is not based on the personal knowledge of the witness, but is being offered to prove the truth of the matter asserted, falls under which rule of evidence? Hearsay rule
- Evidence that is convincing or measures up without question is known as _ sufficient evidence
- Evidence that is convincing or measures up without question is known as __________. Sufficient evidence
- Evidence that is material to the case or has bearing on the matter at hand is known as __________. relevant evidence
- Evidence that must be legally qualified and reliable is known as __________. competent evidence
- Evidence that must be legally qualified and reliable is known as competent evidence
- File timestamps can be helpful if you have ____. Recorded any time offset between the system clock and real time
- From a forensics perspective, Linux systems have the same artifacts as Windows systems. False
- If you change the extension of the file, the magic number will remain unaltered. True
- In a Windows operating system, many artifacts are stored here. in the registry
- It is a good idea to hash log files and place the logs on a read-only, write-once media. True
- Of the following, which is the most volatile location of stored data? CPU storage
- Oral testimony that proves a specific fact with no inferences or presumptions is which type of evidence? Direct evidence
- Placing a cell phone in a RF isolation bag is important so the phone is not remotely wiped. True
- Slack space occurs when files are saved when the size is less than a cluster
- Tangible objects that prove or disprove fact are what type of evidence? Real evidence
- Tangible objects that prove or disprove fact are what type of evidence? Real evidence
- The term __________ describes a series of digits near the beginning of the file that provides information about the file format. magic number
- There is no recovery from data that has been changed. True
- What is a software bomb? Software that can destroy or modify files when commands are executed on the computer
- What name is given to a logical storage unit that is subsequently used by an operating system? Partition
- What type of evidence is used to aid a jury and may be in the form of a model, experiment, chart, and so on, to indicate that an event occurred? Demonstrative evidence
- When deleted, a file is removed from its original place on the storage device and is only available in the recycle bin. False
- When performing forensics on a computer system, you should use the utilities provided by that system False
- Which of the following has the least volatile data? Hard disk
- Which of the following has the least volatile data? Hard disk
- Which rule applies to evidence obtained in violation of the Fourth Amendment of the Constitution? Exclusionary rule
- Which rule applies to evidence obtained in violation of the Fourth Amendment of the Constitution? Exclusionary rule
Other Links:
See other websites for quiz:
Check on QUIZLET