Week 4 - Searching for Evidence Flashcards

1
Q

What stages come before the Search stage of the investigation?

A

Indentificaiton
Acquisition
Preservation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What piece of data is being more commonly investigated?

A

Web history and wed search history. It is not eact proof of criminal activity itself, but it can provide insight into the character of the accused and can lend credibility to a case.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the search stage of investigation?

A

This is the search of evidencial data on the digital devices that can help uncover the truth about the crime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is something that must be considered when searching for evidence?

A

Different spellings of files or searches, including common mispellings. If these are not consider, then any search that was spelled incorrectly will go unnoticed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What parts of the disk image are searched during investigation?

A

Partitions
Unallocated space
Host protected area

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What can the HPA contain?

A

Misc files and data not found on the original partitions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the two types of search?

A

Physical

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the two subtypes of logical search?

A

Brute force

Directed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What happens in the physical search?

A

When the image is treated as a lump of data, rather than different file systems. It looks for bit patterns in the data as a whole.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens in the logical search?

A

When the files in the image are examinated individually. A file system is required in the image as part of the search.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What kind of data can physical search help you find?

A

It can help reveal deliberate attempts at concealment. Since physical search avoids the file system, it can find things that are hidden from the file system as it looks at data in the HPA, file slack, unallocated space and bad blocks which might not be visible otherwise.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is file carving?

A

It is used in physical search. It tries to find patterns or associations with one part of the data and another.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the limitations of physical search?

A

It cannot cope with zip files, compressed files, or encrypted files.
It can take a long time, as it analyses all available data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What must you do to prepare for a logical search?

A

The image must be mounted so that the file system becomes accessable. This means it must be attached to the investigative machine and treated as a disk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is string search?

A

A type of method used in physical search that looks for the prescense of strings and words in the bit data as a whole.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly