ETC ETC Digital & Electronic Evidence 2 — Questions and Answers
Question 1: What legal authority is generally required before law enforcement can search the contents of a seized digital device?
- A search warrant specifically authorizing the search of the device's contents (Correct answer)
- The same warrant used to search the physical premises
- Verbal consent from any adult present at the scene
- An arrest warrant for the device's owner
Correct answer: A search warrant specifically authorizing the search of the device's contents
Per Riley v. California (2014), the US Supreme Court ruled that law enforcement generally needs a separate search warrant to search the digital contents of a cell phone.
Question 2: An evidence technician seizes a laptop that is encrypted with BitLocker. What should be done to preserve potential access?
- Keep it powered on if possible, document any visible passwords/recovery keys, and transport it safely to avoid sleep mode (Correct answer)
- Immediately power it off and submit to the lab
- Force-boot from a USB drive to bypass encryption
- Contact the manufacturer to unlock it remotely
Correct answer: Keep it powered on if possible, document any visible passwords/recovery keys, and transport it safely to avoid sleep mode
Keeping the encrypted laptop powered on may preserve the decryption key in RAM, and recovery keys displayed or written nearby may be needed to access the drive later.
Question 3: What is metadata and why is it important in digital evidence investigations?
- Data about data — it includes creation dates, GPS coordinates, and author information that can place evidence in time and location (Correct answer)
- The main content of a digital file such as text or images
- The file name extension that indicates file type
- A digital watermark added by forensic tools
Correct answer: Data about data — it includes creation dates, GPS coordinates, and author information that can place evidence in time and location
Metadata embedded in files (EXIF data in photos, document properties) can reveal when a file was created, modified, where it was taken (GPS), and by whom.
Question 4: Which type of digital evidence storage media requires special anti-static precautions during collection and transport?
- Hard drives, SSDs, and RAM modules are susceptible to electrostatic discharge (ESD) damage (Correct answer)
- USB flash drives only
- Optical discs (CDs/DVDs) only
- Memory cards used in cameras
Correct answer: Hard drives, SSDs, and RAM modules are susceptible to electrostatic discharge (ESD) damage
Electronic storage media components are sensitive to electrostatic discharge, which can corrupt or destroy data; anti-static bags must be used during collection and transport.
Question 5: What is the purpose of creating a forensic image (bit-stream copy) rather than simply copying files from a digital device?
- A forensic image captures every bit including deleted files, slack space, and unallocated sectors that file copying misses (Correct answer)
- A forensic image is faster than copying files manually
- A forensic image automatically decrypts protected files
- A forensic image creates a compressed archive for storage efficiency
Correct answer: A forensic image captures every bit including deleted files, slack space, and unallocated sectors that file copying misses
A bit-stream forensic image copies every sector of the media, preserving deleted files, file system metadata, slack space, and unallocated areas that simple file copying skips.
Question 6: When documenting the seizure of a network router as digital evidence, what information should be photographed before disconnecting it?
- All status indicator lights, cable connections and labeled ports, and any visible configuration information (Correct answer)
- Only the front of the device for identification purposes
- The router's default password label on the bottom
- The power adapter and cable only
Correct answer: All status indicator lights, cable connections and labeled ports, and any visible configuration information
Photographing the router's indicator lights, labeled cable connections, and configuration data preserves the network state and documents how devices were connected before seizure.
What legal authority is generally required before law enforcement can search the contents of a seized digital device?