NEW
Font size
WorksheetsData Acquisition Quiz
Total questions: 41
Worksheet time: 21mins
In digital forensics, data acquisition refers to:
Editing digital evidence for better clarity
Copying data from electronic media for investigation
Encrypting and storing forensic data
Deleting unused data from storage devices
Which of the following is not a type of data acquisition mentioned?
Static acquisition
Live acquisition
Hybrid acquisition
Both A and B are mentioned
Static acquisitions capture data that:
Changes frequently while being collected
Is not accessed or altered by other processes
Exists only in RAM memory
Is encrypted during the acquisition process
Why are live acquisitions becoming more common in newer operating systems?
Because they are faster
Due to increased use of whole disk encryption
Because static acquisitions are no longer possible
Live acquisitions require less training
One disadvantage of live acquisition is that:
It cannot collect RAM data
Metadata such as date and time values may change during acquisition
It does not work on encrypted drives
It alters the original media permanently
Making a second live acquisition while a computer is running will:
Collect the exact same data
Collect new data due to OS changes
Fail due to encryption
Be identical to static acquisition
The primary goal of static acquisition is:
Encrypt the data for security
Preserve digital evidence reliably
Compress the data for storage
Modify evidence for presentation
Why learn multiple acquisition tools?
To reduce costs
Because some tools may fail during acquisition
To make data harder to recover
To speed up investigation
The older open-source disk-to-image format is:
AFF
E01
Raw
FAT
An advantage of raw format is:
Requires less storage
Can ignore minor read errors
Cannot be read by most tools
Always compresses automatically
A disadvantage of raw format is:
Incompatible with Linux tools
Requires storage equal to original disk size
Cannot do bit-by-bit copying
Has a 650 MB limit
Which hashing functions are used for validating raw acquisitions?
CRC32, MD5, SHA-1
AES, SHA-2, RSA
SHA-256, Blowfish, CRC16
MD5, DES, SHA-512
Proprietary formats may include all except:
Image compression options
Metadata integration
Image splitting into segments
Unlimited cross-vendor compatibility
Developer of Advanced Forensic Format (AFF):
Guidance Software team
Dr. Simson L. Garfinkel
Microsoft Security Division
Basis Technology Engineers
Which is not a design goal of AFF?
No size restriction for disk-to-image files
Internal consistency checks
Vendor-specific implementation restrictions
Extensibility
In AFF, .afm is used for:
Segmented image files
Metadata
Compressed volumes only
FAT partition maps
Preferred acquisition type for digital evidence:
Live acquisition
Static acquisition
Logical acquisition
Sparse acquisition
Live acquisition is performed when:
Computer is off
Drive is not encrypted
Encrypted drive is accessible while powered on/logged in
Drive is damaged
Which is not one of the four data collection methods?
Disk-to-image file
Disk-to-disk copy
Logical disk-to-data file
Cloud-to-cloud copy
Most common method offering flexibility:
Sparse acquisition
Logical acquisition
Disk-to-image file
Disk-to-disk copy
Method capturing only specific files:
Static acquisition
Logical acquisition
Disk-to-disk copy
Lossless compression
Sparse acquisition also collects:
All files on the drive
Fragments of unallocated data
Compressed image only
File system metadata
Preferred method in e-discovery for large storage systems:
Logical acquisition
Sparse acquisition
Live acquisition
Static acquisition
Lossy compression is avoided because:
It is slow
It alters original data
Not compatible with MD5
Requires expensive tools
Lossless compression can reduce size by up to:
25%
50%
75%
90%
If drive contains many zip files, compression:
Greatly reduces size
Has little effect
Damages files
Converts them to lossy format
To verify lossless compression integrity:
Count files
Use MD5 and SHA-1 before and after
Open in WinZip
Compare file sizes only
Which is not a concern when acquiring RAID data?
Type of RAID
Storage needed
OS FAT32 support
Capability of acquisition tool
Older RAID 1 sometimes required:
One drive connected
Both drives connected
Conversion to RAID 0
Lossy compression
Proprietary format with compression on RAID data:
Increases storage
Reduces storage
Makes data unreadable
Removes need for RAID knowledge
Tools supporting RAID acquisition:
EnCase
X-Ways Forensics
FTK
All of the above
Tool copying RAID to raw file for restoration:
R-Studio
RAID Reconstructor
EnCase
FTK
When dealing with large RAID servers, you should:
Break array into single drives
Consult vendor for best capture method
Use JPEG compression
Convert to proprietary format only
Remote acquisition tools allow:
Installing new OS
Acquiring disk data or fragments over a network
Seizing the computer physically
Encrypting all files
Most remote acquisitions are:
Static
Live
Sparse only
Disk-to-disk copy
Some tools copy data secretly by:
Sending phishing email
Pushing remote access program via encrypted link
Installing antivirus
Forcing reboot
A major benefit of remote acquisition:
Requires no skills
Saves time and reduces chance of detection
Works only with wireless networks
Requires no permissions
Remote acquisitions usually require:
Admin privileges to push agents
Physical possession of drive
Antivirus license
Disabling network card
Which could hinder remote acquisition?
Lossless compression
Antivirus/antispyware/firewall tools
MD5 hashing
Proprietary format
How can security tools allow remote access programs?
Disable encryption
Configure to ignore remote access programs
Uninstall firewall
Force safe mode
Suspects may detect remote acquisition because:
They can install security tools with alarms
It always triggers OS updates
Tools leave visible icons
All require restarts
