โ† All CFE Flashcard Decks

Digital Evidence Collection and Preservation Flashcards

7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Evidence Collection and Preservation flashcards as text
  1. When imaging a suspect's SSD, a forensic examiner should be aware that SSDs may alter data through a process called:

    Answer: Wear leveling and TRIM operations

    SSDs use wear leveling to distribute writes evenly and TRIM to erase unused blocks, which can destroy deleted data before or during imaging.

  2. In the context of cloud forensics, which challenge is most unique compared to traditional digital forensics?

    Answer: Data may be stored across multiple jurisdictions on shared infrastructure

    Cloud data is often distributed across multiple geographic locations and shared hardware, creating jurisdictional and data segregation challenges unique to cloud forensics.

  3. A forensic examiner discovers a file with a .jpg extension but analysis reveals it is actually a ZIP archive. This technique is known as:

    Answer: File signature spoofing or file masquerading

    File masquerading involves changing a file's extension to disguise its true type; file signature (magic bytes) analysis reveals the actual format.

  4. Which Windows artifact is most useful for determining which USB devices were previously connected to a system?

    Answer: SYSTEM registry hive (USBSTOR key)

    The USBSTOR key in the Windows SYSTEM registry hive records details about every USB storage device that has been connected to the system.

  5. During network forensics, a packet capture shows traffic encrypted with TLS. Without the private key, the examiner should focus on:

    Answer: Metadata such as IP addresses, ports, timestamps, and session duration

    Even without decrypting TLS content, metadata like endpoints, timing, and volume can provide significant investigative value.

  6. The 'order of volatility' principle in digital forensics dictates that examiners should collect:

    Answer: The most volatile data first, proceeding to less volatile sources

    The order of volatility requires collecting the most transient data (RAM, CPU registers) first because it is lost soonest, before moving to less volatile sources like hard drives.

  7. What does 'chain of custody' documentation for digital evidence primarily establish?

    Answer: A chronological record of who controlled, handled, or transferred the evidence

    Chain of custody documentation creates an unbroken record of every person who accessed or handled evidence, ensuring its admissibility and integrity in legal proceedings.