State public disclosure laws apply to state records, but FOIA allows citizens to request copies of public documents created by federal agencies.
Computerstored records are data the system maintains, such as system log files and proxy server logs.
An emergency situation under the PATRIOT Act is defined as the immediate risk of death or personal injury, such as finding a bomb threat in an email.
To investigate employees suspected of improper use of company digital assets, a company policy statement about misuse of digital assets allows corporate investigators to conduct covert surveillance with little or no cause, and access company computer systems and digital devices without a warrant.
The Fourth Amendment states that only warrants “particularly describing the place to be searched and the persons or things to be seized” can be issued. The courts have determined that this phrase means a warrant can authorize a search of a specific place for
Physically copying the entire drive is the only type of datacopying method used in software acquisitions.
A keyword search is part of the analysis process within what forensic function?
What program serves as the GUI front end for accessing Sleuth Kit’s tools?
Software forensics tools are grouped into commandline applications and GUI applications
What hex value is the standard indicator for jpeg graphics files?
In general, what would a lightweight forensics workstation consist of?
When performing disk acquisition, the raw data format is typically created with the UNIX/Linux _____________ command.
Reconstructing fragments of files that have been deleted from a suspect drive, is known as ____________ in North America.
What tool below was written for MSDOS and was commonly used for manual digital investigations?
Passwords are typically stored as oneway _____________ rather than in plaintext.
Making a logical acquisition of a drive with whole disk encryption can result in unreadable files.
In what mode do most writeblockers run?
What option below is an example of a platform specific encryption tool?
All forensics acquisition tools have a method for verification of the datacopying process that compares the original drive with the image.
Which of the following options is not a subfunction of extraction?
What algorithm is used to decompress Windows files?
What is the goal of the NSRL project, created by NIST?
The __________ Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack, dcfldd, MemFetch, and MBoxGrep, and utilizes a KDE interface.
The physical data copy subfunction exists under the ______________ function.
What is the purpose of the reconstruction function in a forensics investigation?