Podcast
Questions and Answers
What is the primary focus of digital forensics?
What is the primary focus of digital forensics?
- Developing new techniques for data gathering
- Enhancing security event response times
- Improving digital device performance
- Collecting and protecting information related to security events (correct)
What document provides guidelines for evidence collection and archiving in digital forensics?
What document provides guidelines for evidence collection and archiving in digital forensics?
- ISO 27001
- COBIT 5
- RFC 3227 (correct)
- NIST 800-53
What are the three phases of the digital forensics process described in RFC 3227?
What are the three phases of the digital forensics process described in RFC 3227?
- Identifying, containing, and eradicating
- Gathering, examining, and documenting
- Acquisition, analysis, and reporting (correct)
- Collection, preservation, and presentation
What is often requested by legal counsel as a precursor to other legal proceedings?
What is often requested by legal counsel as a precursor to other legal proceedings?
What is the term for the data copied for a legal hold, which is often stored in a separate repository?
What is the term for the data copied for a legal hold, which is often stored in a separate repository?
Why is it important to be detail-oriented in digital forensics?
Why is it important to be detail-oriented in digital forensics?
What is a possible source to consult when examining the time zone settings of a device?
What is a possible source to consult when examining the time zone settings of a device?
Where can you find log information in a Linux operating system?
Where can you find log information in a Linux operating system?
Why is it important to perform user interviews quickly after a security event?
Why is it important to perform user interviews quickly after a security event?
What is the purpose of documenting the data acquisition process?
What is the purpose of documenting the data acquisition process?
What is a challenge of gathering witness statements?
What is a challenge of gathering witness statements?
What is the final step in the security event analysis process?
What is the final step in the security event analysis process?
What is the primary responsibility of a security professional when receiving a legal hold?
What is the primary responsibility of a security professional when receiving a legal hold?
What type of information can be provided by video that is normally not available?
What type of information can be provided by video that is normally not available?
Why is it important to archive video content?
Why is it important to archive video content?
What is a concern regarding the data collected during a security incident?
What is a concern regarding the data collected during a security incident?
What is the purpose of documenting the chain of custody?
What is the purpose of documenting the chain of custody?
Why is it important to document the time zone information associated with the device being examined?
Why is it important to document the time zone information associated with the device being examined?
What is the purpose of using hashes during the collection process?
What is the purpose of using hashes during the collection process?
What is a common concern when collecting data from a mobile device?
What is a common concern when collecting data from a mobile device?
Why is it important to follow proper procedures when gathering data?
Why is it important to follow proper procedures when gathering data?
What is the purpose of maintaining a central database of collected data?
What is the purpose of maintaining a central database of collected data?
Flashcards are hidden until you start studying