AccessData: Case Creation and Processing
19 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

When creating a new case, which of the following fields are required?

  • Case Description, Examiner Name, Evidence Location
  • Examiner Initials, Case Notes, Hash Value List
  • Case Name, Case Folder Directory, Processing Profile (correct)
  • Evidence Type, Time Zone, Case Number

Customizing processing options is only possible when initially creating a case and cannot be modified later.

False (B)

What are two ways you can refine evidence during the evidence processing stage?

Type/Status, Date/Size

When refining the index, you can exclude items by global or __________ categories.

<p>specific</p> Signup and view all the answers

Which of the following is NOT a type of evidence that can be selected when managing evidence in a case?

<p>Network Logs (C)</p> Signup and view all the answers

When adding forensic images as evidence, which of the following options is available?

<p>Add all images within a directory (A)</p> Signup and view all the answers

When FTK converts FAT times to GMT, the time is converted to local time in the case database.

<p>False (B)</p> Signup and view all the answers

What consideration should be given to removable media regarding FTK time zone settings?

<p>Removable media should get the settings of associated computers if they exist. (A)</p> Signup and view all the answers

Name two examiner template options available for cases after creation.

<p>Full, Reduced</p> Signup and view all the answers

Changes made in the 'Processing Options' are a one time change or can be saved in a __________ profile for later use.

<p>custom</p> Signup and view all the answers

Processing options must be customized or modified per case.

<p>False (B)</p> Signup and view all the answers

What time zone are FAT times converted to in the case database?

<p>GMT</p> Signup and view all the answers

When refining evidence by Type/Status, what does this process primarily determine?

<p>The inclusion or exclusion of specific items in the case. (B)</p> Signup and view all the answers

When dealing with removable media and time zone settings, the system should attempt to get the settings of associated ______ if they exist.

<p>computers</p> Signup and view all the answers

Match the evidence selection options with their corresponding descriptions:

<p>Acquired Image = A single forensic image file obtained through imaging. All Images in Directory = Includes all forensic images present within a specified folder. Contents of Directory = Includes all files and folders within a live file system directory. Physical Drive = Represents an entire physical storage device.</p> Signup and view all the answers

What is the purpose of examiner templates?

<p>To provide different levels of detail upon opening a case. (A)</p> Signup and view all the answers

Changes made to processing options are always saved to a custom profile for later use.

<p>False (B)</p> Signup and view all the answers

Besides Type/Status, what is another option for refining evidence during case creation?

<p>Date/Size</p> Signup and view all the answers

During Index Refinement, what is the effect of excluding specific categories?

<p>It prevents those categories from being displayed in search results. (B)</p> Signup and view all the answers

Flashcards

AccessData Case

A named container for forensic investigations, containing evidence and settings.

Required Case Fields

Case Name, Case Folder Directory, and Processing Profile.

Processing Profile

A set of pre-defined or custom settings that dictates how evidence is processed.

Customize Processing

Customize processing rules, evidence refinement, index refinement, and custom file identifiers.

Signup and view all the flashcards

Evidence Refinement

Options to include or exclude items based on type/status, date, or size.

Signup and view all the flashcards

Index Refinement

Options to include or exclude items from the index based on type/status, date, or size.

Signup and view all the flashcards

Case Evidence Types

Forensic images (acquired images or images in directory) and live evidence (files, directories, drives).

Signup and view all the flashcards

Evidence Group

Used to logically group related pieces of evidence within a case.

Signup and view all the flashcards

FTK Time Zone Handling

FTK converts FAT times to GMT in the case database to standardize time representation.

Signup and view all the flashcards

Examiner Templates

Full (all features) or Reduced (limited features) views available after case creation.

Signup and view all the flashcards

New Case Creation

The initial steps taken to set up a new investigation within AccessData.

Signup and view all the flashcards

Profile Selection

Choosing a pre-configured or customized set of processing rules.

Signup and view all the flashcards

Processing Options Adjustments

Modifying the settings that dictate how evidence is processed and indexed.

Signup and view all the flashcards

Managing Evidence

Selecting and organizing the digital evidence to be included in the case.

Signup and view all the flashcards

Evidence Refinement Choices

Options to specify what types of files or data are included or excluded from the case.

Signup and view all the flashcards

Index Refinement Choices

Options to control what data gets indexed for faster searching.

Signup and view all the flashcards

Types of Case Evidence

Acquired images or all images in directory; Contents of directory, individual file, Physical drive, Logical drive.

Signup and view all the flashcards

Examiner Template Options

Selection of either 'Full' feature set or 'Reduced' feature set, saved per examiner.

Signup and view all the flashcards

Template Differences

Full template unlocks all features while reduced only has commonly used features.

Signup and view all the flashcards

Study Notes

  • This module covers AccessData case creation.
  • Includes new case creation steps, profile selection, processing options adjustments, managing evidence, and examiner templates.

Creating and Opening Cases

  • To create a new case, navigate to File > Cases > New

Creating a New Case

  • Creating a new case requires three fields.
  • Namely Case Name, Case Folder Directory, and Selecting a Processing Profile.
  • All other fields are optional.

Processing Profile Selection

  • Can select either a prebuilt processing profile or a custom evidence processing profile.

Customize Processing Options

  • Processing options can be customized or modified per case
  • Changes to processing options may be desired for processing options, evidence refinement, index refinement, and/or custom file identifiers.

Processing Options

  • All processing options are available in the detailed options.
  • Changes made to processing options can be either for one time use or saved in a custom profile for later use.

Evidence Refinement

  • Choices made here will define which items from the evidence are included in the case.
  • Excluded items will not be visible within the case.
  • One can refine by Type/Status or Date/Size.

Index Refinement

  • Choices will determine what evidence is inculded or excluded in the Index.
  • Can refine by Type/Status or Date/Size.
  • Can exclude by global or specific categories.

Manage Evidence

  • Evidence can be managed by the user here.

Selecting Case Evidence

  • The user will be able to select case evidence.
  • Forensic Images can be added, which include Acquired Image, and All Images in a Directory.
  • Live Evidence can be added, which includes Contents of Directory, Individual File, Physical Drive, and Logical Drive.

Evidence Group

  • You can allow the user to group evidence items.

Refinement Options

  • You can select which Refinement Options to use for the current case

FTK Time Zone Settings

  • FTK requires the selection of a time zone for all evidence items.
  • FAT times are converted to GMT in the case database.
  • For removable media, use the settings of associated computers if they exist.
  • If the previous settings do not exist, use local settings.

Examiner Templates

  • Choosing a template provides options for "Full" and "Reduced"
  • Templates are available upon repeatedly opening cases after creation
  • Can be set by choosing the "Remember Selection" option.

Studying That Suits You

Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

Quiz Team

Related Documents

Description

Learn how to create a new case in AccessData, including selecting processing profiles and customizing processing options. This module covers managing evidence, adjusting processing options, and using examiner templates for efficient case handling. Master case creation steps and profile selection for effective digital investigations.

More Like This

Use Quizgecko on...
Browser
Browser