CrFA CrFA Digital Forensics & Data Analysis 1 — Questions and Answers
Question 1: Which federal standard governs the admissibility of digital evidence in U.S. federal courts?
- Federal Rules of Evidence Rule 901 (Correct answer)
- Daubert Standard
- Frye Standard
- Sarbanes-Oxley Act Section 802
Correct answer: Federal Rules of Evidence Rule 901
Federal Rules of Evidence Rule 901 requires authentication of digital evidence by showing it is what the proponent claims it to be.
Question 2: A forensic accountant uses a write blocker when imaging a hard drive primarily to:
- Speed up the imaging process
- Prevent alteration of the original evidence (Correct answer)
- Encrypt the copied data
- Compress the disk image
Correct answer: Prevent alteration of the original evidence
A write blocker prevents any data from being written to the original drive, preserving the integrity of the evidence.
Question 3: When analyzing financial data for fraud, which ACL/IDEA function is most useful for identifying duplicate invoice payments?
- Stratification
- Benford's Law analysis
- Duplicate key detection (Correct answer)
- Aging analysis
Correct answer: Duplicate key detection
Duplicate key detection compares fields such as invoice number, vendor, and amount to flag transactions that appear more than once.
Question 4: Benford's Law is most effective in detecting fraud when applied to which type of dataset?
- Assigned sequential numbers like ZIP codes
- Naturally occurring financial amounts across a wide range (Correct answer)
- Fixed salary payments
- Inventory count sheets with uniform item quantities
Correct answer: Naturally occurring financial amounts across a wide range
Benford's Law applies to naturally occurring data spanning several orders of magnitude, where the leading digits follow a predictable logarithmic distribution.
Question 5: During e-discovery in a forensic accounting investigation, metadata is important because it can reveal:
- The market value of assets in dispute
- When a document was created, modified, or accessed (Correct answer)
- The creditworthiness of the defendant
- The tax basis of transferred property
Correct answer: When a document was created, modified, or accessed
File metadata such as creation date, last modified date, and author information can help establish timelines and detect document tampering.
Question 6: A chain of custody document in a digital forensics investigation is maintained to:
- Summarize findings for the jury
- Track who handled evidence and when, ensuring its integrity (Correct answer)
- Record billable hours during the investigation
- Document the client's cooperation with investigators
Correct answer: Track who handled evidence and when, ensuring its integrity
Chain of custody establishes a documented record of every person who accessed evidence, protecting against claims of tampering or contamination.
Which federal standard governs the admissibility of digital evidence in U.S. federal courts?