Digital Evidence Collection & Preservation Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Evidence Collection & Preservation flashcards as text
What does the acronym 'MACB' refer to in NTFS timestamp analysis?
Answer: Modified, Accessed, Changed, Born
MACB stands for Modified, Accessed, Changed (MFT entry changed), and Born (created), representing the four timestamps stored in NTFS MFT entries for each file.
An investigator is collecting evidence from a crime scene involving cryptocurrency transactions. Which type of storage media is most critical to locate?
Answer: Hardware wallets and devices storing private keys
Hardware wallets store private keys in dedicated secure chips and represent direct control over cryptocurrency funds, making them the highest priority item in cryptocurrency investigations.
What is 'timestamp manipulation' and why is it forensically significant?
Answer: The deliberate alteration of file system timestamps to obscure when files were created or modified
Timestamp manipulation is the intentional changing of file system timestamps to hide or alter the timeline of events, which is forensically significant as it represents evidence tampering.
During evidence packaging, what should be used to package hard drives to protect against electrostatic discharge?
Answer: Anti-static bags and foam padding
Hard drives must be packaged in anti-static bags to prevent electrostatic discharge damage, combined with foam padding for physical shock protection during transport.
What is the primary difference between a logical acquisition and a physical acquisition of a mobile device?
Answer: Logical acquisition is faster but only captures allocated files; physical acquisition captures the entire memory chip including deleted data
Logical acquisition extracts only allocated, accessible files through the OS, while physical acquisition captures a bit-for-bit image of the memory including deleted and unallocated space.
When collecting RAM from a live system using a tool like WinPmem or DumpIt, what critical information must be recorded about the acquisition?
Answer: The system time, running processes, and tool version used during capture
Documenting the system time, running processes, and acquisition tool version during RAM capture establishes context for later analysis and satisfies chain of custody requirements.
A forensic examiner finds that a suspect used CCleaner before law enforcement arrived. What is the most likely forensic impact?
Answer: Temporary files, browser history, and some deleted file remnants may have been wiped from free space
CCleaner typically wipes temporary files, browser artifacts, and may overwrite free space, but a thorough forensic examination may still recover data from unaffected areas and log files.