Exam 4: Data Acquisition

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Unlike RAID 0, RAID 3 stripes tracks across all disks that make up one volume.

Free
(True/False)
4.8/5
(38)
Correct Answer:
Verified

False

Match each item with a statement below: -ILook imaging tool

Free
(Multiple Choice)
4.7/5
(39)
Correct Answer:
Verified

E

Linux ISO images are referred to as ____.

Free
(Multiple Choice)
4.8/5
(34)
Correct Answer:
Verified

B

Typically, a(n) ____ acquisition is done on a computer seized during a police raid, for example.

(Multiple Choice)
4.7/5
(41)

The ____ command creates a raw format file that most computer forensics analysis tools can read, which makes it useful for data acquisitions.

(Multiple Choice)
4.8/5
(42)

Explain the sparse data copy method for acquiring digital evidence.

(Essay)
4.8/5
(41)

There are two types of acquisitions: static acquisitions and ____________________ acquisitions.

(Short Answer)
4.9/5
(41)

Match each item with a statement below: -process of copying data

(Multiple Choice)
4.8/5
(38)

Match each item with a statement below: -example of a lossless compression tool

(Multiple Choice)
4.9/5
(36)

EnCase Enterprise is set up with an Examiner workstation and a Secure Authentication for EnCase (____) workstation

(Multiple Choice)
4.9/5
(33)

For computer forensics, ____ is the task of collecting digital evidence from electronic media.

(Multiple Choice)
4.8/5
(41)

SafeBack performs a(n) ____ calculation for each sector copied to ensure data integrity

(Multiple Choice)
4.7/5
(41)

The ____ command displays pages from the online help manual for information on Linux commands and their options.

(Multiple Choice)
4.8/5
(35)

What are some of the main characteristics of Linux ISO images designed for computer forensics?

(Essay)
4.7/5
(36)

What are the advantages and disadvantages of using raw data acquisition format?

(Essay)
4.9/5
(33)

What are some of the design goals of AFF?

(Essay)
4.8/5
(36)

Image files can be reduced by as much as ____% of the original.

(Multiple Choice)
4.8/5
(39)

The ____ DOS program En.exe requires using a forensic MS-DOS boot floppy or CD and a network crossover cable.

(Multiple Choice)
4.8/5
(34)

Dr. Simson L. Garfinkel of Basis Technology Corporation recently developed a new open-source acquisition format called ____________________.

(Short Answer)
4.8/5
(38)

If the computer has an encrypted drive, a ____ acquisition is done if the password or passphrase is available.

(Multiple Choice)
4.9/5
(34)
Showing 1 - 20 of 50
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)