Search Header Logo

Gathering Evidence

Authored by Katherine Newport-forbes

Computers

9th - 12th Grade

Used 116+ times

Gathering Evidence
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

8 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

What are some reasons for not pulling the plug on a computer that may contain evidence(check all that apply)

Any evidence on RAM is under threat of destruction

Interacting with a running computer in any way causes changes to the system

Sudden loss of power could damage the data

System may be unencrypted when powered on but return to an encrypted stage when powered off

2.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

What are some reasons to pull the plug on a computer that may contain evidence(check all that apply)

Any evidence on RAM is under threat of destruction

Interacting with a running computer in any way causes changes to the system

Sudden loss of power could damage the data

Change to a system may invalidate evidence

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which type of evidence is the least volatile

Data on hard disk

Routing table

CPU

Temporary file system/swap space

4.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which are the ideal ways to isolate a cell phone that may contain evidence(check all that apply)

Access data via find my phone

Turn it off

Put it in a Faraday bag

Put it in an empty paint can

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is a clone?

Member of the republic's army

bit-for-bit copy of a hard drive

A program for file carving

Copy-and-pasted copy of a hard drive

6.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Why is it important to clone hard drives that may contain evidence?(check all that apply)

Clone gets data in unallocated space such as deleted or partially overwritten files

Clone also gets file system data

Clones allow for a "do over" if investigation alters the system

Clones only get active data

7.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

In what circumstances might an investigator have to clone a drive on site?(check all that apply)

If they do not have the proper warrants to take the drive to a lab

If the device is a personal computer

If the device is a server generating revenue for a business

If the investigation is a missing persons case

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?