CREST CPIA LATEST UPDTE 2024 QUESTIONS

Study Guides Aug 15, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

CREST CPIA LATEST UPDTE 2024 QUESTIONS

AND VERIFIED CORRECT ANSWERS

GUARANTEED SUCCES S

Accidental Breach Causes - CORRECT ANSWER: 1. Data Transportation

  • Misconfigured Settings
  • Misinterpretation of Instructions

4. OSINT

  • Loss of Data
  • Insider Threat

ACPO - CORRECT ANSWER: 1. Association of Chief Police Officers

  • They issued standardised forensic acquisition guidelines for police officers in the UK

ACPO Guidelines - Principle 1 - CORRECT ANSWER: No action taken by law

enforcement agencies or their agents should change data held on a computer or storage media which may subsequently be relied upon in court.

ACPO Guidelines - Principle 1 in Practise - CORRECT ANSWER: 1. Overarching

principle, should be adhered to unless:

  • Volatile evidence may be lost
  • Steps are required to secure disk image or logical evidence
  • You believe that you must make steps to better secure evidence as above

ACPO Guidelines - Principle 2 - CORRECT ANSWER: In circumstances where a

person finds it necessary to access original data held on a computer or on storage media, that person must be competent to do so and be able to give evidence explaining the relevance and the implications of their actions.

ACPO Guidelines - Principle 2 in Practise - CORRECT ANSWER: 1. You must be

experienced, "qualified" and able to reason and document your decision

2. When making changes, you should record:

  • What changes are made
  • What the implications are
  • Why you have chosen this action and what may be lost if you don't

ACPO Guidelines - Principle 3 - CORRECT ANSWER: An audit trail or other record of all processes applied to computer based electronic evidence should be created and 1 / 2

preserved. An independent Third Party should be able to examine those processes and achieve the same result.

ACPO Guidelines - Principle 3 in Practise - CORRECT ANSWER: 1. Investigation log - personal log

  • Document imaging process - record any hash values you have for later integrity
  • check

  • Document processes applied with each piece of forensic software
  • Thoroughly document difficult to find evidence, explain how you got there

ACPO Guidelines - Principle 4 - CORRECT ANSWER: The person in charge of the

investigation (the case officer) has overall responsibility for ensuring that the law and these principles are adhered to

ACPO Guidelines - Principle 4 in Practise - CORRECT ANSWER: 1. The Case Officer

is required to brief team and be clear on objectives, principles and methodologies

  • Any breaches to be clearly reported and options discussed

Adhering to RFC 3227 (Guidelines for Evidence Collection and Archiving). The following list can be used (most to least volatile) - CORRECT ANSWER: 1. Registers, Cache

  • Routing table, ARP Cache, process table, kernel stats, memory
  • Temporary file systems
  • Disk
  • Remote logging and monitoring data that is relevant to the system in question
  • Physical configuration, network topology
  • Archival media

Bootkits - CORRECT ANSWER: 1. More expensive to develop than rootkits

  • Bootkits are specials kinds of Rootkit
  • Possible to maintain persistence by overwriting MBR
  • Bootskits typically load before the kernel
  • / 2

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Study Guides
Added: Aug 15, 2025
Description:

CREST CPIA LATEST UPDTE 2024 QUESTIONS AND VERIFIED CORRECT ANSWERS GUARANTEED SUCCES S Accidental Breach Causes - CORRECT ANSWER: 1. Data Transportation 2. Misconfigured Settings 3. Misinterpretat...

Get this document $30.00