Digital Evidence and Forensic Investigation: Lecture 4

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/59

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:10 PM on 10/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

60 Terms

1
New cards

What is digital evidence

Information stored, transmitted, or received by an electronic device that can be used in an investigation.

2
New cards

What are examples of digital evidence

Emails, text messages, photos/videos, Internet searches, social media, databases, call logs, GPS data, and browsing history.

3
New cards

What are the general steps of a digital-forensics investigation

Identify devices/resources → preserve data → analyze → document → present.

4
New cards

How do U.S. courts treat digital evidence

Digital evidence is accepted as physical evidence and digital data is treated as a tangible object.

5
New cards

What is SWGDE

The Scientific Working Group on Digital Evidence, which sets standards for recovering, preserving, and examining digital evidence.

6
New cards

Why are consistent evidence-handling practices important

They help verify your work and improve your credibility.

7
New cards

Why is digital evidence different from other physical evidence

It can be changed more easily.

8
New cards

How can investigators detect changes to digital evidence

By comparing the original data with a duplicate.

9
New cards

What is hearsay

Secondhand or indirect evidence offered to prove the truth of a statement.

10
New cards

What are the two types of computer records

Computer-stored records and computer-generated records.

11
New cards

What are computer-stored records

Records containing human statements, such as emails, documents, chat logs, and messages.

12
New cards

Are computer-stored records usually hearsay

Yes, because they contain human statements and must meet a hearsay exception to be admissible.

13
New cards

What are computer-generated records

Records created automatically by a computer, such as log files, packet captures, and ATM receipts.

14
New cards

Are computer-generated records usually hearsay

No, because they generally do not contain human statements.

15
New cards

When is a computer-generated record considered authentic

When the program that created it was functioning properly.

16
New cards

How can metadata help authenticate evidence

Metadata can help identify who created a record, such as the author of a Word document.

17
New cards

What is the best evidence rule

To prove the contents of a document, recording, or photograph, the original is normally required.

18
New cards

Can a duplicate sometimes be used instead of the original

Yes, the Federal Rules of Evidence can allow a properly produced duplicate.

19
New cards

Can properly created bit-stream copies be admitted in court

Yes, although the slides say they are not considered the best evidence.

20
New cards

What does FOIA allow

Citizens can request copies of public documents created by federal agencies.

21
New cards

What can a corporate misuse policy allow investigators to do

Investigate company systems with little or no cause and access them without a warrant.

22
New cards

Why should companies display warning banners

To state that they reserve the right to inspect computing assets.

23
New cards

What is the main concern of private-sector investigators

Protecting company assets and enforcing company policy.

24
New cards

What should happen if a company investigation uncovers a crime

Inform management, stop the investigation as needed, and avoid violating Fourth Amendment restrictions.

25
New cards

What is credible cause used for

To determine whether law enforcement may arrest, search property, or obtain a warrant.

26
New cards

What does a search warrant authorize

Search and seizure of specific evidence related to the criminal complaint.

27
New cards

What is the plain view concept

Evidence seen by an officer who is legally present may sometimes be seized without a warrant.

28
New cards

What are the three requirements for plain view

The officer is legally present, senses are not enhanced by technology, and the discovery happens by chance.

29
New cards

Why is plain view limited in digital forensics

Discovering unrelated digital evidence may require an additional or expanded warrant before continuing the search.

30
New cards

What is an important first step when assigned a digital case

Identify the nature of the case and whether it is public or private sector.

31
New cards

What determines whether computers can be removed from a scene

The type of case and the location of the evidence.

32
New cards

What should happen if removing a business computer would harm the business

Acquire the evidence without removing the computer from the site.

33
New cards

Who is usually in charge of a large law-enforcement investigation

A designated lead investigator.

34
New cards

What specialists might be needed at a digital crime scene

Specialists in operating systems, RAID servers, or databases.

35
New cards

What is an initial-response field kit

A lightweight kit containing only essential tools needed to quickly secure and capture evidence.

36
New cards

What is an extensive-response field kit

A larger kit containing a wider range of tools for more thorough on-site investigation.

37
New cards

What is the goal of processing a crime or incident scene

Collect and secure digital evidence.

38
New cards

Why is a slow response dangerous

Digital evidence can be lost.

39
New cards

What should investigators establish around a scene

A secure perimeter, potentially using yellow barrier tape.

40
New cards

Why can “professional curiosity” be dangerous

People who are not part of the investigation team can accidentally destroy evidence.

41
New cards

Should investigators immediately cut power to a running computer

No; they should not cut power without consulting a supervisor.

42
New cards

What should investigators document on a live computer

Active windows, shell sessions, and everything they do while copying data.

43
New cards

What information should be placed on evidence tags

Date/time, serial numbers or unique features, make/model, and collector’s name.

44
New cards

How many people should collect and log evidence

The slides recommend assigning one person.

45
New cards

What information should investigators look for around the scene

Passwords, PINs, bank accounts, encryption keys, documentation, software, and backup media.

46
New cards

What does a digital-forensics technical advisor do

Helps select tools, locate evidence, handle large RAID systems, prepare warrants, secure scenes, and document activities.

47
New cards

Why should investigators document every step

So another investigator can repeat the process and reproduce the same results.

48
New cards

What should happen to original media after imaging

It should be secured in an evidence locker.

49
New cards

Which hash algorithms are specifically named in lecture 4

MD5 and SHA-1.

50
New cards

What is the purpose of hashing

To verify the integrity and authenticity of evidence and show it has not been altered.

51
New cards

Can you predict the hash value of a file

No.

52
New cards

Does each evidence file need its own hash

Yes, so investigators can verify that specific file has not changed.

53
New cards

What lifespan do the slides give CDs/DVDs

About 2–5 years.

54
New cards

What lifespan do the slides give solid-state USB drives

Around 10 years under normal usage.

55
New cards

What lifespan do the slides give magnetic data tapes

Up to about 30 years.

56
New cards

What is Super-DLT designed for

Large RAID data backups.

57
New cards

Should investigators rely on only one storage method

No; the slides recommend making two image copies and using different tools/storage media.

58
New cards

How should access to evidence storage be controlled

Restrict lab access and maintain a visitor sign-in roster.

59
New cards

What does an evidence custody form contain

Evidence identification, who handled it, and the dates/times it was handled.

60
New cards

What type of bag should be used for electronic components

An antist