4_5_1 Section 5 – Operations and Incident Response - 4.5 – Digital Forensics- Digital Forensics
22 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

What is the primary focus of digital forensics?

  • Developing new techniques for data gathering
  • Enhancing security event response times
  • Improving digital device performance
  • Collecting and protecting information related to security events (correct)
  • What document provides guidelines for evidence collection and archiving in digital forensics?

  • ISO 27001
  • COBIT 5
  • RFC 3227 (correct)
  • NIST 800-53
  • What are the three phases of the digital forensics process described in RFC 3227?

  • Identifying, containing, and eradicating
  • Gathering, examining, and documenting
  • Acquisition, analysis, and reporting (correct)
  • Collection, preservation, and presentation
  • What is often requested by legal counsel as a precursor to other legal proceedings?

    <p>Legal hold</p> Signup and view all the answers

    What is the term for the data copied for a legal hold, which is often stored in a separate repository?

    <p>Electronically stored information (ESI)</p> Signup and view all the answers

    Why is it important to be detail-oriented in digital forensics?

    <p>Because some of this information could be used later on in a court of law</p> Signup and view all the answers

    What is a possible source to consult when examining the time zone settings of a device?

    <p>Configuration settings for the operating system</p> Signup and view all the answers

    Where can you find log information in a Linux operating system?

    <p>/var/log directory</p> Signup and view all the answers

    Why is it important to perform user interviews quickly after a security event?

    <p>Because people may forget or inaccurately describe the event</p> Signup and view all the answers

    What is the purpose of documenting the data acquisition process?

    <p>To provide step-by-step information about the data gathering process</p> Signup and view all the answers

    What is a challenge of gathering witness statements?

    <p>They may not be 100% accurate</p> Signup and view all the answers

    What is the final step in the security event analysis process?

    <p>Documenting conclusions and inferences</p> Signup and view all the answers

    What is the primary responsibility of a security professional when receiving a legal hold?

    <p>To gather and maintain the data to preserve everything</p> Signup and view all the answers

    What type of information can be provided by video that is normally not available?

    <p>Screen information and system details</p> Signup and view all the answers

    Why is it important to archive video content?

    <p>So that it can be viewed later in reference to a security incident</p> Signup and view all the answers

    What is a concern regarding the data collected during a security incident?

    <p>That it may not be admissible in a court of law</p> Signup and view all the answers

    What is the purpose of documenting the chain of custody?

    <p>To verify that nothing has been changed since the data was collected</p> Signup and view all the answers

    Why is it important to document the time zone information associated with the device being examined?

    <p>To ensure that the timestamps are accurate</p> Signup and view all the answers

    What is the purpose of using hashes during the collection process?

    <p>To verify that the data is the same as when it was collected</p> Signup and view all the answers

    What is a common concern when collecting data from a mobile device?

    <p>That the data may not be authorized to be collected</p> Signup and view all the answers

    Why is it important to follow proper procedures when gathering data?

    <p>To ensure that the data is collected correctly</p> Signup and view all the answers

    What is the purpose of maintaining a central database of collected data?

    <p>To catalog and document everything that has been collected</p> Signup and view all the answers

    More Like This

    Use Quizgecko on...
    Browser
    Browser