NEW
Font size
WorksheetsChapter 2 eCDFP
Total questions: 11
Worksheet time: 6mins
What are the types of data acquisitions?
Static & dynamic acquisitions
Passive & aggressive acquisitions
CTRL+C & CTRL+V acquisitions
RAM & hard drive acquisitions
What is the storage format that is used by EnCase?
Expert Witness Format (EWF)
Encrypted Waffle Format (EWF)
EnCase File Format (EFF)
Logical Volume Format (LVF)
Imaging vs Copying
Imaging is an exact bit-by-bit copy of an entire device & copying transfers only visible data
Imaging only copies the visible files & copying makes an exact duplicate of the entire device
Imaging copies only deleted files & copying copies every single bit perfectly
Imaging is when you take a selfie of your hard drive, and copying is like photocopying your documents
What is the function of the Volatility framework?
To analyze volatile memory (RAM) dumps for forensic artifacts
To permanently delete files from a hard drive
To extract running processes and other live system info
To magically reboot your computer into forensic mode with a single click
The command “volatility --profile=Win7SP1x64 pstree -f memory.dmp” will?
Display running processes in a hierarchical tree showing parent-child relationships
Hide any suspicious processes from the memory dump
Show active network connections related to running processes
Remove malware processes from the memory dump
Which of the following correctly describes Bulk Extractor’s input and output?
image or dump file + output directory = report files
copied files + backup folder = compressed archive
live network traffic + decryption key = password list
hard drive + time machine = backups from the future
What tool is used to hash data?
HashCalc
DataWiper
Hashbrowns
HashExplorer
As an investigator, why do you use a write blocker?
To prevent modification of the original evidence
To speed up the imaging process
To make a backup copy automatically
To make sure the evidence stays in its original outfit
What is the purpose of the “secure” option on live response tool (BriMor Labs)?
To password protect the acquired data
To encrypt the suspect’s device during collection
To prevent live response tools from using system resources
To make investigators feel like secret agents with passwords
Advanced Forensic Format (AFF) is a closed file format used to store disk images and metadata in digital forensics
True
False
Kinda true
Kinda false
Imaging = From disk drive to disk drive & Cloning = From disk drive to image file
True
False
Kinda true
Kinda false
