CCE Legal & Ethical Issues in Digital Forensics 4 โ Questions and Answers
Question 1: Which act criminalizes unauthorized access to computer systems and is most commonly applied in computer crime prosecutions in the US?
- Electronic Espionage Act
- Computer Fraud and Abuse Act (CFAA) (Correct answer)
- Digital Millennium Copyright Act
- Cybersecurity Information Sharing Act
Correct answer: Computer Fraud and Abuse Act (CFAA)
The CFAA (18 U.S.C. ยง 1030) is the primary federal statute criminalizing unauthorized access to protected computers.
Question 2: A forensic examiner working a civil case is deposed by opposing counsel. The examiner's primary obligation is to:
- Protect the interests of the client who hired them
- Provide truthful, accurate testimony regardless of which side hired them (Correct answer)
- Refuse to answer questions outside the original engagement
- Defer all technical questions to the retaining attorney
Correct answer: Provide truthful, accurate testimony regardless of which side hired them
Expert witnesses have a duty to the court to provide truthful and objective testimony, regardless of who retained them.
Question 3: What is the primary purpose of obtaining written consent before conducting a forensic examination of a personally-owned device?
- To satisfy vendor licensing requirements
- To protect the examiner legally and establish a valid legal basis for the search (Correct answer)
- To allow the device owner to monitor the examination
- To create a billable documentation record
Correct answer: To protect the examiner legally and establish a valid legal basis for the search
Written consent provides a legal basis for the search without a warrant and protects the examiner from claims of unauthorized access.
Question 4: The Health Insurance Portability and Accountability Act (HIPAA) impacts digital forensics investigations primarily by:
- Requiring all forensic examiners to obtain HIPAA certification
- Restricting disclosure of protected health information found during an investigation (Correct answer)
- Mandating that medical devices be excluded from forensic scope
- Requiring hospitals to allow warrantless searches
Correct answer: Restricting disclosure of protected health information found during an investigation
HIPAA's Privacy and Security Rules restrict how protected health information (PHI) may be accessed, used, and disclosed, even during investigations.
Question 5: Which principle requires a forensic examiner to document all steps taken during an investigation so findings can be independently reproduced?
- Non-repudiation
- Reproducibility (Correct answer)
- Chain of custody
- Authenticity
Correct answer: Reproducibility
Reproducibility ensures that another qualified examiner following the same documented steps would arrive at the same findings.
Question 6: A forensic examiner finds evidence of a crime unrelated to the original investigation scope while executing a valid warrant. This is best described as:
- An illegal expansion of the warrant
- A plain view discovery requiring further legal authority before seizure (Correct answer)
- Automatically within scope if found on the same device
- Exigent circumstances allowing immediate arrest
Correct answer: A plain view discovery requiring further legal authority before seizure
Evidence found in plain view during a lawful search may be noted but typically requires additional legal authority (e.g., an expanded warrant) before it can be seized and used.
Question 7: The ethical principle of 'objectivity' in forensic examination means the examiner should:
- Always support the findings requested by the hiring party
- Report all findings accurately regardless of how they affect the case (Correct answer)
- Focus only on inculpatory evidence
- Withhold exculpatory evidence to strengthen the prosecution
Correct answer: Report all findings accurately regardless of how they affect the case
Objectivity requires reporting all findings truthfully, including exculpatory evidence, without bias toward any party.
Which act criminalizes unauthorized access to computer systems and is most commonly applied in computer crime prosecutions in the US?