1/20
Flashcards covering key vocabulary and concepts in digital forensics based on the lecture notes.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Digital Forensics
The investigation and analysis tools and techniques used to determine what happened on a system or device.
Legal Hold
A notification sent by opposing counsel to preserve and retain data relevant to a legal matter.
Chain of Custody
The process of maintaining and documenting the handling of evidence to ensure its integrity.
E-Discovery
The process of obtaining electronic evidence during legal proceedings.
Order of Volatility
A principle used in digital forensics to identify which data should be captured first based on its likelihood of being lost.
Forensic Data Acquisition
The process of collecting data from electronic devices in a manner that maintains its integrity for legal purposes.
Spoliation of Evidence
The intentional, reckless, or negligent alteration, destruction, or hiding of evidence relevant to legal matters.
FTK Imager
A tool used to create forensic images and capture live memory from systems.
WinHex
A disk editing tool used for acquiring disk images and editing data from various sources.
Right-to-audit Clause
A contractual agreement that allows an organization the right to audit a cloud service provider.
Nonrepudiation
The assurance that someone cannot deny the validity of something, often related to the integrity of data.
Hashing
A process used to create a unique identifier for data, which can verify the integrity of the data.
Cloud Forensics
The practice of forensic analysis for data stored in cloud environments, presenting unique challenges.
Network Forensics
The analysis and capturing of network traffic to support forensic investigation.
Slack Space
Unused space on a hard drive that may still contain remnants of deleted files.
Forensic Report
A document summarizing the findings, processes, and tools used in a forensic investigation.
Admissibility of Evidence
Criteria determining if the evidence can be used in court, based on relevance and legality.
Electronic Discovery Reference Model (EDRM)
A framework that outlines the various stages of the e-discovery process.
Acquisition Tools
Software or hardware used to capture a forensic image of data from devices.
Data Breach Notification Laws
Regulations that require organizations to notify individuals in the event of a data breach.
Firmware
The permanent software programmed into a read-only memory of a device, which can also contain forensic data.