4.5 key aspects of digital forensics Flashcards

1
Q

order of volatility

A

most volatile data to capture first:

CPU, Ram
Memory, tables, kernel
temporary file systems
disk
remote data
physical configurations
archival media

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

swap/pagefile

A

a system file that creates temporary storage space on a hard disk or solid-state drive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

snapshot

A

for virtual machines
point-in-time system image

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

cache

A

store data for later use and is cached in CPU, disk, internet, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

hashing integrity

A

digital fingerprint for cryptographic integrity thru hashing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

checksum integrity

A

simple integrity check
protects from accidental changes during transmission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

provenance integrity

A

documentation of origination
data handling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly