โ† All ALISON Flashcard Decks

Digital Forensics & Cybercrime Investigation Flashcards

6 cards from real ALISON practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Digital Forensics & Cybercrime Investigation flashcards as text
  1. What does 'live forensics' refer to in digital investigations?

    Answer: Forensics performed on systems that are currently powered on and running

    Live forensics involves collecting volatile data (RAM, running processes, network connections) from a powered-on system before shutting it down.

  2. Which Windows artifact stores recently accessed files and is valuable to forensic investigators?

    Answer: Link files (LNK files)

    Windows LNK (shortcut) files automatically created in Recent Items contain metadata about accessed files including timestamps and original file paths.

  3. What is the purpose of the Windows Registry in a forensic investigation?

    Answer: It records system configuration, user activity, and installed software that can reveal attacker behavior

    The Windows Registry contains keys tracking program execution, USB connections, recently accessed files, and persistence mechanisms used by malware.

  4. What type of file system artifact allows forensic investigators to recover deleted files on NTFS volumes?

    Answer: Master File Table ($MFT)

    The NTFS Master File Table ($MFT) retains metadata about deleted files even after deletion, enabling partial or full file recovery.

  5. What is 'steganography' and why is it relevant to digital forensics?

    Answer: Hiding data within ordinary-looking files like images to conceal communications or exfiltrate data

    Steganography conceals data inside carrier files, and forensic investigators must detect and extract hidden content during investigations.

  6. Which log file in Linux systems is most useful for tracking user authentication events during a forensic investigation?

    Answer: /var/log/auth.log

    The /var/log/auth.log file on Debian/Ubuntu systems records all authentication attempts, sudo usage, SSH logins, and account changes.