Lesson 12 - Group 2: Digital Forensics

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/16

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:31 PM on 7/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

17 Terms

1
New cards
Digital forensics
Collecting and analyzing evidence from computer systems to a standard that may be accepted in court.
2
New cards
Due process
Evidence-collection and analysis procedures designed to ensure fairness.
3
New cards
Legal hold
Authority or requirement to preserve and potentially seize systems or information as evidence.
4
New cards
Order of volatility
Collecting the most temporary and easily lost evidence before less volatile evidence.
5
New cards
What is the evidence order shown in Lesson 12?
CPU registers and cache, RAM, persistent storage, remote logs and monitoring data, physical configuration and network topology, and archival media.
6
New cards
System memory acquisition
Collecting evidence from nonpersistent memory, including temporary filesystems, registry data, network connections, and cryptographic keys.
7
New cards
Why must volatile memory normally be collected while a system is running?
Its contents can be lost when the system is powered off.
8
New cards
Disk image acquisition
Creating a forensic image of nonvolatile storage media or devices.
9
New cards
Live versus static disk acquisition
Live acquisition images a running system; static acquisition occurs after shutting down the host or disconnecting power.
10
New cards
Write blocker
A control that prevents changes from being written to evidence media during acquisition or analysis.
11
New cards
Why are cryptographic hashes used in forensics?
To verify evidence integrity and demonstrate that the source, forensic image, and analysis copy have not changed.
12
New cards
What evidence items should be hashed?
The source device, the reference image, and the copy used for analysis.
13
New cards
Chain of custody
Documentation of evidence possession, transfer, handling, analysis, storage, and presentation.
14
New cards
What physical controls support evidence preservation?
Tamper-evident packaging, secure storage, and protection from environmental hazards.
15
New cards
What principles should guide forensic reporting?
The analysis should be unbiased, repeatable, and should not alter or manipulate evidence.
16
New cards
E-discovery
Identifying, preserving, searching, tagging, deduplicating, and disclosing electronically stored information.
17
New cards
ESI
Electronically Stored Informatio