4_5_1 Section 5 – Operations and Incident Response - 4.5 – Digital Forensics- Digital Forensics
22 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

What is the primary focus of digital forensics?

  • Developing new techniques for data gathering
  • Enhancing security event response times
  • Improving digital device performance
  • Collecting and protecting information related to security events (correct)
  • What document provides guidelines for evidence collection and archiving in digital forensics?

  • ISO 27001
  • COBIT 5
  • RFC 3227 (correct)
  • NIST 800-53
  • What are the three phases of the digital forensics process described in RFC 3227?

  • Identifying, containing, and eradicating
  • Gathering, examining, and documenting
  • Acquisition, analysis, and reporting (correct)
  • Collection, preservation, and presentation
  • What is often requested by legal counsel as a precursor to other legal proceedings?

    <p>Legal hold</p> Signup and view all the answers

    What is the term for the data copied for a legal hold, which is often stored in a separate repository?

    <p>Electronically stored information (ESI)</p> Signup and view all the answers

    Why is it important to be detail-oriented in digital forensics?

    <p>Because some of this information could be used later on in a court of law</p> Signup and view all the answers

    What is a possible source to consult when examining the time zone settings of a device?

    <p>Configuration settings for the operating system</p> Signup and view all the answers

    Where can you find log information in a Linux operating system?

    <p>/var/log directory</p> Signup and view all the answers

    Why is it important to perform user interviews quickly after a security event?

    <p>Because people may forget or inaccurately describe the event</p> Signup and view all the answers

    What is the purpose of documenting the data acquisition process?

    <p>To provide step-by-step information about the data gathering process</p> Signup and view all the answers

    What is a challenge of gathering witness statements?

    <p>They may not be 100% accurate</p> Signup and view all the answers

    What is the final step in the security event analysis process?

    <p>Documenting conclusions and inferences</p> Signup and view all the answers

    What is the primary responsibility of a security professional when receiving a legal hold?

    <p>To gather and maintain the data to preserve everything</p> Signup and view all the answers

    What type of information can be provided by video that is normally not available?

    <p>Screen information and system details</p> Signup and view all the answers

    Why is it important to archive video content?

    <p>So that it can be viewed later in reference to a security incident</p> Signup and view all the answers

    What is a concern regarding the data collected during a security incident?

    <p>That it may not be admissible in a court of law</p> Signup and view all the answers

    What is the purpose of documenting the chain of custody?

    <p>To verify that nothing has been changed since the data was collected</p> Signup and view all the answers

    Why is it important to document the time zone information associated with the device being examined?

    <p>To ensure that the timestamps are accurate</p> Signup and view all the answers

    What is the purpose of using hashes during the collection process?

    <p>To verify that the data is the same as when it was collected</p> Signup and view all the answers

    What is a common concern when collecting data from a mobile device?

    <p>That the data may not be authorized to be collected</p> Signup and view all the answers

    Why is it important to follow proper procedures when gathering data?

    <p>To ensure that the data is collected correctly</p> Signup and view all the answers

    What is the purpose of maintaining a central database of collected data?

    <p>To catalog and document everything that has been collected</p> Signup and view all the answers

    More Like This

    Digital Forensics Overview
    13 questions
    Digital Evidence Overview
    40 questions
    Digital Forensics Overview
    45 questions

    Digital Forensics Overview

    UndisputableAgate7525 avatar
    UndisputableAgate7525
    Use Quizgecko on...
    Browser
    Browser