โ† All CFE Flashcard Decks

Digital Evidence Collection and Preservation Flashcards

7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Evidence Collection and Preservation flashcards as text
  1. A forensic examiner finds that a suspect used a portable OS (e.g., Tails Linux) booted from a USB drive. What is the most significant implication for the investigation?

    Answer: Little or no evidence of the session may remain on the host computer's hard drive

    Live operating systems like Tails run entirely in RAM and are designed to leave minimal traces on the host machine's storage, severely limiting evidence recovery.

  2. In Windows forensics, the $I30 index entry in an NTFS directory is forensically significant because:

    Answer: It may retain entries for deleted files even after they are removed from the MFT

    The $I30 directory index in NTFS can retain slack entries for files that were previously in the directory and later deleted, providing evidence of their prior existence.

  3. When collecting volatile network data from a live system, which command captures active network connections and their associated process IDs on a Windows system?

    Answer: netstat -ano

    The command 'netstat -ano' displays all active TCP/UDP connections, listening ports, and the PID of the associated process, which is critical volatile evidence.

  4. A forensic examiner receives a hard drive that was used in a RAID 5 array. The most critical first step before imaging is to:

    Answer: Document the RAID configuration, stripe size, and disk order to enable proper reconstruction

    RAID 5 data is striped across multiple disks, so the stripe size, disk order, and parity configuration must be documented to reconstruct the virtual volume correctly from individual images.

  5. Which international standard provides guidance on the collection and preservation of digital evidence?

    Answer: ISO/IEC 27037

    ISO/IEC 27037 provides internationally recognized guidelines for identification, collection, acquisition, and preservation of digital evidence.

  6. A suspect's encrypted VeraCrypt volume is mounted and open at the time of seizure. What is the best immediate action?

    Answer: Image the decrypted volume while it is mounted before shutting down

    When an encrypted volume is already mounted and accessible, the examiner should immediately image the decrypted volume, as shutting down will lock the encrypted data behind the passphrase.

  7. The term 'acquisition hash' in a forensic report refers to:

    Answer: A cryptographic hash of the evidence taken immediately after imaging to verify integrity

    An acquisition hash is a cryptographic value (e.g., MD5, SHA-256) computed from the forensic image immediately after creation to serve as a baseline for verifying the image has not been altered.