Week 1 - Obstacles Flashcards

1
Q

What are four obstalces to digital forensic analysis?

A

Quantity of data
Passwords
Hidden Data
Deleted Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain the obstacle Quantity of data. What, why and effectiveness?

A

Devices have a lot of data on them, lots of irrelevent data. Furthermore, there are many devices to consider and analyse. e.g. Phone, PC, Console.
Lots of data means lots of time, storage and resources is required for analysis. This obstacle is effective and serious.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain the obstacle Passwords. What, why and effectiveness?

A

Passwords can be strong because of encryption.

In investigations however, passwords offer no protection for data if the data can be isolated, retrieved and copied out of the host system during investigation. Thus this is not really an obstacle for digital forensics and is thus not effective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain the obstacle Hidden Data. What, why and effectiveness?

A

Data can be concealed in various ways to hide it from investigation. However, data analysis software will always correctly identify the true nature of the data. Since tools can identify true natures, its less of an obstacle and more of a tedious task. Thus, its less effective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some ways to hide data?

A

Camoflaged files
Marking files as ‘hidden’
Scattered Data (Stored in unallocated space)
Slack space (The space at the ‘end’ of files)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is slack space?

A

The unused space between the end of the actual file and the end of the defined data unit (cluster) in storage. When a file is written, the does not occupy the entire cluster, the remaining space is slack space.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a cluster?

A

The smallest unit of storage that the opertating system can deal with.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a cluster?

A

The smallest unit of storage that the opertating system can deal with. A cluster is normally only allocated to one file/data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly