Sett 2 Flashcards
Which is not a formal position in a forensics lab?
Investigator, manager, analyst, legal manager
Legal manager
What are the CERT standards for a forensic laboratory?
ASCLD (American Society of Crime Laboratory Directors) does the test and their process is based on ISO 17025:2005.
Which role develops and forces lab policies?
lab manager
What role is testifying the facts of data gathered?
Analyst
Which is not a service offered by a forensics lab?
Adversary emulation
Parking lot security and biometric authentication are what level security?
Lab level 4
Physical control, neither, or tech control?
Fencing
ballards
identity management
firewalls
security
training
procedures
Fencing, ballards phys
identity management, firewalls, security tech
training, procedures neutral
Cc television is what physical security control?
Preventative, detective, corrective, recovery, deterrent, or compensate
Detective
George needs a forensics package that is free to use and can examine images of hard drives. What should he use?
Autopsy
Ken is a lead investigator, he surveys a crime scene. What tool will not contaminate digital evidence?
Write Blocker
Company is closing, highly sensitive data is on their systems what sanitization method must be used?
Destroy
Which is not a santitization term?
Wipe
Maintained by SANS to help with forensic issues?
SIFT
What company does specification for data sanitization standards?
NIST (National Institute of Standards Technology)
Which org certifies free tools to examine images on a hard drive?
CFTT (The Computer Forensics Tool Testing) Handbook
Before you seize any evidence what must you have?
A warrant
As a member of her organization’s IS team, Larissa is performing a data forensic investigation involving 3 members of the corporate finance team. Before Larissa can seize any evidence from the suspects employee’s computer, she must have an active warrant? True or False
False
5th amendment is search and seizure? True or False
False/4th amendment is search and seizure
Going to a judge with a request to seize digital evidence the request must provide what?
Probable cause
Evidence may be seized without a warrant if people are in danger, these are called what?
Exigent circumstances
Seize evidence if you see incriminating evidence?
Plain view doctrine
Cyber policy employee system might be monitored, this policy is called what?
Login banner
Michelle is completing an affidavit for review with a judge. Which of the following would she not include in the document?
A reference number to the approved warrant
What does the dd command do? sudo dd command?
Used to make a forensic bit-by-bit copy of a drive to a number of locations.
Disk to disk
disk to image
disk to network
sudo runs that shit with admin priv maybe idk