โ† All ETC Flashcard Decks

ETC Digital & Electronic Evidence Flashcards

6 cards from real ETC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 ETC Digital & Electronic Evidence flashcards as text
  1. What is the order of volatility in digital forensics, and why does it matter to evidence technicians?

    Answer: Most volatile data (RAM, cache) must be collected first before less volatile data (hard drive, backups), as it is lost most quickly

    The order of volatility dictates that evidence technicians collect the most ephemeral data first (RAM, network state, running processes) before it is lost, followed by persistent storage.

  2. An evidence technician receives a damaged hard drive with a failed read head. What is the appropriate action?

    Answer: Submit it to a specialized digital forensics lab for clean-room data recovery without attempting to access it

    A hard drive with a failed read head requires clean-room recovery by specialists; any attempt to run the drive further risks permanent platter damage and data loss.

  3. GPS devices seized as evidence may contain which types of potentially valuable investigative data?

    Answer: Saved waypoints, route history, recent destinations, and track logs that can establish location at specific times

    GPS devices store waypoints, route history, and track logs that can forensically place a person at specific locations at specific times relevant to the investigation.

  4. What does the term 'chain of custody' mean specifically in the context of digital evidence?

    Answer: A documented record of every person who accessed or handled the digital evidence from collection through court presentation

    Chain of custody for digital evidence tracks every person who handled or accessed the device or image, proving it has not been altered or tampered with.

  5. When collecting social media evidence, what method ensures the content is preserved in a legally defensible manner?

    Answer: Using specialized forensic web capture tools or certified screenshots with metadata, rather than simple screenshots

    Forensic web capture tools preserve metadata (timestamps, URLs, page source) that authenticate social media content as unaltered, making it admissible in court.

  6. Which federal law governs the interception of electronic communications and must be considered when collecting digital evidence?

    Answer: Electronic Communications Privacy Act (ECPA) and the Wiretap Act

    The ECPA and Wiretap Act govern the collection and use of stored and intercepted electronic communications, requiring proper legal authority before accessing such data.