Chapter 1 Flashcards

(30 cards)

1
Q

What is the definition of forensics?

A

The use of science and technology to investigate and establish facts in criminal or civil courts of law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the subject of computer forensics?

A

The extraction of data in a consistent, scientific manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is latent evidence?

A

Evidence that can take many forms.

Laten = hidden such as fingerprints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the definition of computer forensics according to US-CERT?

A

Forensics is the process of using scientific knowledge for collecting, analyzing, and presenting evidence to the courts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does computer forensics generally consider?

A

The use of analytical and investigative techniques to identify, collect, examine and preserve evidence/information which is magnetically stored or encoded.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the objective of computer forensics?

A

To recover, analyze, and present computer-based material as evidence in a court of law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What devices can be the subject of computer forensics?

A

Both network servers, personal computers, laptops and smartphones, routers, tablets, printers, GPS devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the goal of computer forensics?

A

To obtain evidence that can be used in some legal proceeding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the first step in computer forensics?

A

Understanding computer hardware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is one issue with the current practice of forensics?

A

Too many individuals want to enter the field without adequate computer backgrounds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the basic knowledge required for mastering forensics?

A

Understanding of computer hardware
Understanding of the operating system
Understanding of computer networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the assumption made while presenting the material in the book?

A

The reader has zero knowledge of computers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a key factor in becoming better at computer forensics?

A

Knowing more about computers and networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What changes very slowly, if at all, in the field of computer forensics?

A

The various file systems and the role of volatile and non-volatile memory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the first step in computer forensics investigation?

A

Collecting the evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What determines if the evidence is admissible in court?

A

How you collect the evidence

17
Q

What is the most time-consuming part of a forensic investigation?

A

Analyzing the data

18
Q

What is the final step in a forensic investigation?

A

Presenting the evidence

19
Q

What are the two most basic forms of presenting evidence in a forensic investigation?

A

Expert report and expert testimony

20
Q

What is an expert report in the context of forensic investigation?

A

A document that lists the tests conducted, findings, and conclusions

21
Q

What is included in an expert report along with the tests conducted, findings, and conclusions?

A

The expert’s curriculum vitae (CV)

22
Q

What is the first step in creating an expert report?

A

Listing the expert’s qualifications

23
Q

What is the purpose of an expert report in computer forensics?

A

To detail the analysis used and tools applied

24
Q

What are the two scenarios in which an expert witness gives testimony?

A

Deposition and trial

25
What is U.S. Federal Rule 702 about?
Defining what an expert is and what expert testimony is
26
What does U.S. Federal Rule 703 state about an expert?
An expert may base an opinion on facts or data
27
What does U.S. Federal Rule 704 state about an expert’s opinion?
An expert’s opinion is not objectionable just because it embraces an ultimate issue
28
What does U.S. Federal Rule 705 state about an expert’s testimony?
An expert may state an opinion without first testifying to the underlying facts or data
29
What does U.S. Federal Rule 706 state about expert witnesses?
This rule covers the appointment of neutral experts used to advise the court
30