CJIS Digital Evidence Management 3 — Questions and Answers
Question 1: When documenting a crime scene with digital devices, which method best captures the spatial relationship between devices before collection?
- Audio recording of observations
- Photography and sketching with measurements (Correct answer)
- Verbal description to a witness
- Video of the investigator collecting items
Correct answer: Photography and sketching with measurements
Photography combined with scaled sketches and measurements best documents spatial relationships for court presentation.
Question 2: A seized smartphone is placed in a Faraday bag during transport. What is the PRIMARY purpose of this action?
- To prevent physical damage to the screen
- To prevent remote wiping or data modification via wireless signals (Correct answer)
- To maintain chain of custody paperwork
- To preserve battery life during storage
Correct answer: To prevent remote wiping or data modification via wireless signals
A Faraday bag blocks wireless signals, preventing remote wiping, lock activation, or data changes via cellular, Wi-Fi, or Bluetooth.
Question 3: Which type of metadata records the date and time a file was last accessed on a Windows NTFS system?
- Author metadata
- MACE timestamps (specifically the 'A' timestamp) (Correct answer)
- File header signature
- Slack space data
Correct answer: MACE timestamps (specifically the 'A' timestamp)
NTFS MACE timestamps track Modified, Accessed, Created, and Entry-modified times; the 'A' timestamp records last access.
Question 4: An investigator finds a file with a .jpg extension but forensic analysis shows the file header signature is that of a .zip file. This is an example of:
- File compression
- Anti-forensic file masking or extension spoofing (Correct answer)
- Corrupt file structure
- Normal NTFS behavior
Correct answer: Anti-forensic file masking or extension spoofing
Changing a file's extension to disguise its true type is an anti-forensic technique called file masking or extension spoofing.
Question 5: In digital forensics, what is 'slack space'?
- Unallocated space on a drive never written to
- The space between the end of a file and the end of its last allocated cluster (Correct answer)
- Space reserved for the operating system
- Free space created after defragmentation
Correct answer: The space between the end of a file and the end of its last allocated cluster
Slack space is the unused area between the logical end of a file and the physical end of the last disk cluster allocated to it.
Question 6: A CJIS investigator needs to recover deleted files from a FAT32 USB drive. Which forensic approach is MOST appropriate?
- Format the drive and restore from backup
- Use file carving tools to recover data from unallocated space (Correct answer)
- Run chkdsk to repair the file system
- Copy all visible files to another drive
Correct answer: Use file carving tools to recover data from unallocated space
File carving reconstructs files from raw data in unallocated space based on file header and footer signatures, regardless of file system metadata.
Question 7: Which legal doctrine allows law enforcement to seize digital evidence not specified in a warrant if it is in plain view during lawful execution of the warrant?
- Fruit of the poisonous tree
- Plain view doctrine (Correct answer)
- Exigent circumstances exception
- Good faith exception
Correct answer: Plain view doctrine
The plain view doctrine permits seizure of evidence not named in a warrant when officers are lawfully present and the incriminating nature is immediately apparent.
When documenting a crime scene with digital devices, which method best captures the spatial relationship between devices before collection?