Exam 4: Data Acquisition

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

The ____ command, works similarly to the dd command but has many features designed for computer forensics acquisitions.

(Multiple Choice)
4.8/5
(31)

Current distributions of Linux include two hashing algorithm utilities: md5sum and ____.

(Multiple Choice)
4.8/5
(44)

Match each item with a statement below: -example of a disk-to-disk copy maker tool

(Multiple Choice)
4.8/5
(40)

SnapBack DatArrest can perform a data copy of an evidence drive in ____ ways.

(Multiple Choice)
4.8/5
(27)

Match each item with a statement below: -type of SCSI drive

(Multiple Choice)
4.9/5
(34)

One major disadvantage of ____ format acquisitions is the inability to share an image between different vendors' computer forensics analysis tools.

(Multiple Choice)
4.8/5
(38)

____ is the only automated disk-to-disk tool that allows you to copy data to a slightly smaller target drive than the original suspect's drive.

(Multiple Choice)
4.8/5
(28)

What are the considerations you should have when deciding what data-acquisition method to use on your investigation?

(Essay)
4.8/5
(41)

SnapBack DatArrest runs from a true ____ boot floppy.

(Multiple Choice)
4.9/5
(41)

One advantage with live acquisitions is that you are able to perform repeatable processes.

(True/False)
5.0/5
(40)
Showing 41 - 50 of 50
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)