1/59
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is digital evidence
Information stored, transmitted, or received by an electronic device that can be used in an investigation.
What are examples of digital evidence
Emails, text messages, photos/videos, Internet searches, social media, databases, call logs, GPS data, and browsing history.
What are the general steps of a digital-forensics investigation
Identify devices/resources → preserve data → analyze → document → present.
How do U.S. courts treat digital evidence
Digital evidence is accepted as physical evidence and digital data is treated as a tangible object.
What is SWGDE
The Scientific Working Group on Digital Evidence, which sets standards for recovering, preserving, and examining digital evidence.
Why are consistent evidence-handling practices important
They help verify your work and improve your credibility.
Why is digital evidence different from other physical evidence
It can be changed more easily.
How can investigators detect changes to digital evidence
By comparing the original data with a duplicate.
What is hearsay
Secondhand or indirect evidence offered to prove the truth of a statement.
What are the two types of computer records
Computer-stored records and computer-generated records.
What are computer-stored records
Records containing human statements, such as emails, documents, chat logs, and messages.
Are computer-stored records usually hearsay
Yes, because they contain human statements and must meet a hearsay exception to be admissible.
What are computer-generated records
Records created automatically by a computer, such as log files, packet captures, and ATM receipts.
Are computer-generated records usually hearsay
No, because they generally do not contain human statements.
When is a computer-generated record considered authentic
When the program that created it was functioning properly.
How can metadata help authenticate evidence
Metadata can help identify who created a record, such as the author of a Word document.
What is the best evidence rule
To prove the contents of a document, recording, or photograph, the original is normally required.
Can a duplicate sometimes be used instead of the original
Yes, the Federal Rules of Evidence can allow a properly produced duplicate.
Can properly created bit-stream copies be admitted in court
Yes, although the slides say they are not considered the best evidence.
What does FOIA allow
Citizens can request copies of public documents created by federal agencies.
What can a corporate misuse policy allow investigators to do
Investigate company systems with little or no cause and access them without a warrant.
Why should companies display warning banners
To state that they reserve the right to inspect computing assets.
What is the main concern of private-sector investigators
Protecting company assets and enforcing company policy.
What should happen if a company investigation uncovers a crime
Inform management, stop the investigation as needed, and avoid violating Fourth Amendment restrictions.
What is credible cause used for
To determine whether law enforcement may arrest, search property, or obtain a warrant.
What does a search warrant authorize
Search and seizure of specific evidence related to the criminal complaint.
What is the plain view concept
Evidence seen by an officer who is legally present may sometimes be seized without a warrant.
What are the three requirements for plain view
The officer is legally present, senses are not enhanced by technology, and the discovery happens by chance.
Why is plain view limited in digital forensics
Discovering unrelated digital evidence may require an additional or expanded warrant before continuing the search.
What is an important first step when assigned a digital case
Identify the nature of the case and whether it is public or private sector.
What determines whether computers can be removed from a scene
The type of case and the location of the evidence.
What should happen if removing a business computer would harm the business
Acquire the evidence without removing the computer from the site.
Who is usually in charge of a large law-enforcement investigation
A designated lead investigator.
What specialists might be needed at a digital crime scene
Specialists in operating systems, RAID servers, or databases.
What is an initial-response field kit
A lightweight kit containing only essential tools needed to quickly secure and capture evidence.
What is an extensive-response field kit
A larger kit containing a wider range of tools for more thorough on-site investigation.
What is the goal of processing a crime or incident scene
Collect and secure digital evidence.
Why is a slow response dangerous
Digital evidence can be lost.
What should investigators establish around a scene
A secure perimeter, potentially using yellow barrier tape.
Why can “professional curiosity” be dangerous
People who are not part of the investigation team can accidentally destroy evidence.
Should investigators immediately cut power to a running computer
No; they should not cut power without consulting a supervisor.
What should investigators document on a live computer
Active windows, shell sessions, and everything they do while copying data.
What information should be placed on evidence tags
Date/time, serial numbers or unique features, make/model, and collector’s name.
How many people should collect and log evidence
The slides recommend assigning one person.
What information should investigators look for around the scene
Passwords, PINs, bank accounts, encryption keys, documentation, software, and backup media.
What does a digital-forensics technical advisor do
Helps select tools, locate evidence, handle large RAID systems, prepare warrants, secure scenes, and document activities.
Why should investigators document every step
So another investigator can repeat the process and reproduce the same results.
What should happen to original media after imaging
It should be secured in an evidence locker.
Which hash algorithms are specifically named in lecture 4
MD5 and SHA-1.
What is the purpose of hashing
To verify the integrity and authenticity of evidence and show it has not been altered.
Can you predict the hash value of a file
No.
Does each evidence file need its own hash
Yes, so investigators can verify that specific file has not changed.
What lifespan do the slides give CDs/DVDs
About 2–5 years.
What lifespan do the slides give solid-state USB drives
Around 10 years under normal usage.
What lifespan do the slides give magnetic data tapes
Up to about 30 years.
What is Super-DLT designed for
Large RAID data backups.
Should investigators rely on only one storage method
No; the slides recommend making two image copies and using different tools/storage media.
How should access to evidence storage be controlled
Restrict lab access and maintain a visitor sign-in roster.
What does an evidence custody form contain
Evidence identification, who handled it, and the dates/times it was handled.
What type of bag should be used for electronic components
An antist