Font size
WorksheetsCHFI Module 4 Review
Total questions: 20
Worksheet time: 13mins
Live Data Acquisition involves collecting volatile information that resides in registries,cache and RAM.
True
False
Static Data Acquisition is the gathering of data that remains unaltered even if the system is powered off.
True
False
There are two types of volatile data. They are _____ and ____
Computer Information, server information
System information, network information
Network information, computer information
Server information, system information
Which is the correct Order of Volatility?
- Registers, and cache
- Temporary file systems
- Physical configuration, and network topology
- Routing table, process table, kernel statistics, and memory
- Archival media
- Disk or other storage media
- Remote logging and monitoring data that is relevant to the system in question
- Registers, and cache
- Routing table, process table, kernel statistics, and memory
- Temporary file systems
- Disk or other storage media
- Remote logging and monitoring data that is relevant to the system in question
- Physical configuration, and network topology
- Archival media
It is a preferred practice to use the original machine for building your forensic case.
True
False
There are three steps to the Volatile Data collection methodology. They are (in order):
Step 1: Incident Response Preparation
Step 2: Policy Verification
Step 3: Incident Documentation
Step 1: Incident Documentation
Step 2: Policy Verification
Step 3: Incident Response Preparation
Step 1: Incident Response Preparation
Step 2: Incident Documentation
Step 3: Policy Verification
None of the above
When collecting volatile data you should establish a trusted command shell.
True
False
When collecting volatile data you can assume the integrity of forensic tool output is accurate.
True
False
Static data is considered to be which type of data?:
non-volatile
volatile
Both
None of the above
Examples of static data would include:
emails, word processing documents, Web activity, slack space
ram, cache, BIOS
All of the above
None of the above
How many copies of the original digital evidence should you create?
1
3
2
4
Linux Validation Methods use command lines instead of hardware software tools to gather and validate evidence.
True
False
There are two types of data acquisition. They are:
Bit Stream Image and Timestamps
Live file imaging and Indexing
Bit Stream Image and Backups
Any of the above are acceptable
According to the National Institute of Justice, write protection should be initiated, if available, to preserve and protect original evidence
True
False
Which of the following commands is used to gather data from Linux machines? (Choose two)
dfcld
dd
dcfldd
ddfcl
How many data acquisition formats are there that investigators can use to gather data?
4
2
3
Many
There are two other methods of data acquisition. They are Logical and Sparse.
True
False
Rapid Image 7020 X2 IT, HardCopy 3P, ROADMASSTER-3 2X, and UktraKit are examples of software acquisition and duplication tools.
True
False
Encase Forensic, DriveSpy, R-Drive Image, and RAID Recovery for Windows are examples of software Data Acquisition and Duplication tools.
True
False
READ THIS QUESTION CAREFULLY!!! - Digital evidence validation involves using hash algorithm utilities to create a decimal number that represents the uniqueness of a data set such as a disk drive or file.
True
False
