Computer Forensics Chapter 1 UPDATED ACTUAL Questions and CORRECT Answers
1 view 0 purchase
Course
Computer Forensics
Institution
Computer Forensics
Computer Forensics Chapter 1 UPDATED
ACTUAL Questions and CORRECT
Answers
The American Heritage Dictionary defines __________as "the use of science and technology to
investigate and establish facts in criminal or civil courts of law." - CORRECT ANSWER -
forensics
Generally, __________ is c...
Computer Forensics Chapter 1 UPDATED
ACTUAL Questions and CORRECT
Answers
The American Heritage Dictionary defines __________as "the use of science and technology to
investigate and establish facts in criminal or civil courts of law." - CORRECT ANSWER -
forensics
Generally, __________ is considered to be the use of analytical and investigative techniques to
identify, collect, examine, and preserve evidence or information that is magnetically stored or
encoded. - CORRECT ANSWER - computer forensics
Computer forensics begins with a thorough understanding of what? - CORRECT
ANSWER - computer hardware
The term that is given to testimony taken from a witness or party to a case before a trial is known
as what? - CORRECT ANSWER - deposition
Before you can do any forensic analysis or examination, you have to do what? - CORRECT
ANSWER - collect the evidence
The real difference between a mediocre investigator and a star investigator is the __________. -
CORRECT ANSWER - evidence analysis
__________is information that has been processed and assembled to be relevant to an
investigation, and that supports a specific finding or determination. - CORRECT
ANSWER - Digital evidence
The __________is the continuity of control of evidence that makes it possible to account for all
that has happened to evidence between its original collection and its appearance in court,
preferably unaltered. - CORRECT ANSWER - chain of custody
, __________is data stored as written matter, on paper or in electronic files. - CORRECT
ANSWER - Documentary evidence
__________is information that helps explain other evidence. - CORRECT ANSWER -
Demonstrative evidence
Data about information, such as disk partition structures, and file tables, is called what? -
CORRECT ANSWER - metadata
The process of examining malicious computer code is known as __________. - CORRECT
ANSWER - software forensics
One must be able to show the whereabouts and custody of the evidence, how it was handled and
stored and by whom, from the time the evidence is first seized by a law enforcement officer or
civilian investigator until the moment it is shown in court. This is referred to as what? -
CORRECT ANSWER - chain of custody
Which of the following correctly shows how the instructions in a computer's BIOS are stored? -
CORRECT ANSWER - (EEPROM)
The most common computer hard drives today are __________. - CORRECT ANSWER -
(SATA)
Which of the following options is a common standard file format for executables, object code,
and shared libraries for UNIX-based systems? - CORRECT ANSWER - ELF
Which of the following was the first file system created specifically for Linux? - CORRECT
ANSWER - Extended File System
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller MGRADES. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $10.49. You're not tied to anything after your purchase.