Exam 6: Current Computer Forensics Tools

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

In general, forensics workstations can be divided into what categories? Explain each category.

(Essay)
4.9/5
(45)

Physically copying the entire drive is the only type of data-copying method used in software acquisitions.

(True/False)
4.7/5
(31)

​What is the purpose of the reconstruction function in a forensics investigation?

(Multiple Choice)
4.8/5
(36)

​The ProDiscover utility makes use of the proprietary _______________ file format.

(Multiple Choice)
4.8/5
(40)

The National Software Reference Library has compiled a list of known ___________ for a variety of OSs, applications, and images​.

(Short Answer)
4.7/5
(29)

​When performing disk acquisition, the raw data format is typically created with the UNIX​/ Linux _____________ command.

(Multiple Choice)
4.9/5
(36)

What are the three minimum steps of a basic digital forensics examination protocol?​

(Essay)
5.0/5
(43)

The __________ Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack, ​dcfldd, MemFetch, and MBoxGrep, and utilizes a KDE interface.​

(Multiple Choice)
4.9/5
(38)

The physical data copy subfunction exists under the ______________ function.​

(Multiple Choice)
4.7/5
(39)

The NIST ________________ program establishes guidelines for selecting and using forensics tools.

(Short Answer)
4.9/5
(37)
Showing 41 - 50 of 50
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)