Forensic Analysis Process Flashcards

1
Q

What should be included in a response kit?

A
  • digital camera
  • latex gloves
  • notepads
  • property report for seizing evidence
  • antistatic bags
  • write blocking devices
  • frequency shielding material
  • toolkit
  • misc: power cables, data cables, usb drives
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Program to use USB devices remotely?

A
  • http://virtualhere.com/home

- requires a network connection where the USB keys are plugged in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the free open source forensic tool system?

A
  • Autopsy

- www.sleuthkit.org/autopsy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the order of volatility, from most to least volatile?

A
  1. live system
  2. running
  3. network
  4. virtual
  5. physical
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Forensic Image

A
  • a bit-for-bit copy of the source device, stored in a forensic image format
  • DD, E01, or AFF
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

File signature analysis

A
  • ensures the file extension matches the file type
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What website allows you to search File Signatures based on File Extension?

A
  • https://filesignatures.net
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the steps in FTK to view/mount a forensic image?

A
  1. File > Image Mounting
  2. Mount Image to Drive menu
    2a. Mount Type: Physical and Logical
    2b. Drive Letter (select any letter)
    2c. Mount Method: Block Device/Read Only
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What to include in Forensic Document?

A
  • your narrative
  • pertinent exhibits
  • supporting documentation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly