Slides 8 Flashcards

1
Q

Define Acquisition

A

making a copy of the original drive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define Validation

A

a way to confirm that a tool is functioning as intended

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Write Blocker

A

prevents data writes to a hard disk. acts as bridge between suspect drive and forensic station

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CRC

A

Math algo. that determines whether a files contents have changed– not considered a forensic hashing algorithm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

3 Rules for forensic Hashes

A
  1. you cant predict in the hash value of a file/device.
  2. no two has values can be the same
  3. if anything changes in the file the has value must change
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Scope Creep

A

when an investigation expands beyond the original description.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data Hiding

A

changing or manipulating a file to conceal info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

3 ways to improve image quality

A
  1. Screen resolution
  2. Software
  3. Number of color bits per pixel
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

standard bitmap file formats

A

.bmp

.Jpeg

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

first technique to hide data

A

change the extensions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

other techniques to hide data

A

set up password protection, use encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Demosaicing

A

process of converting raw picture data to another format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Loseless Compression

A

reduces file size without removing data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Lossy Compression

A

Permanetley discards bits of info rector quantization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Steganography

A

hides info inside graphic files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Insertion

A

hidden data is not displayed when viewing host files in its associated program

17
Q

Substitution

A

replaces bits of the host file with other bits of data

18
Q

4 formats for image files

A
  1. EnCase
  2. Raw Files
  3. SMART files
  4. Sleuth Kit
19
Q

Created subfolders

A

Export, Temp, Report

20
Q

formats ENcase outputs images files to:

A

Ex01

E01 (older)