Digital Forensics in Cybersecurity – WGU C840 – Questions & Verified Answers Forensics ✔️Ans - The process of using scientific knowledge for collecting, analyzing, and presenting evidence to the courts. Deals primarily with the recovery and analysis of latent evidence.Expert Report ✔️Ans - A formal document that lists the tests you conducted, what you found, and your conclusions. It also includes your curriculum vita (CV), is very thorough, and tends to be very long. In most cases an expert cannot directly testify about anything not in his or her expert report.Curriculum Vitae (CV) ✔️Ans - Like a resume, only much more thorough and specific to your work experience as a forensic investigator.Deposition ✔️Ans - Testimony taken from a witness or party to a case before a trial; less formal and is typically held in an attorney's office.Digital Evidence ✔️Ans - Information that has been processed and assembled so that it is relevant to an investigation and supports a specific finding or determination.Chain of Custody ✔️Ans - The continuity of control of evidence that makes it possible to account for all that has happened to evidence between its original collection and its appearance in court, preferably unaltered.Objectives of Computer Forensics ✔️Ans - Recover computer-based material Analyze computer-based material Present computer-based material Goals of Opposing Counsel in a Deposition ✔️Ans - To find out as much as possible about your position, methods, conclusions, and even your side's legal strategy 1 / 3
To get you to commit to a position you may not be able to defend later Real Evidence ✔️Ans - A physical object that someone can touch, hold, or
directly observe. Examples: include a laptop with a suspect's fingerprints on
the keyboard, a hard drive, a universal serial bus (USB) drive, or a handwritten note.Documentary Evidence ✔️Ans - Data stored as written matter, on paper or in electronic files; includes memory-resident data and computer files.
Examples: e-mail messages, logs, databases, photographs, and telephone call-
detail records Testimonial Evidence ✔️Ans - Information that forensic specialists use to support or interpret real or documentary evidence Demonstrative Evidence ✔️Ans - Information that helps explain other evidence. An example is a chart that explains a technical concept to the judge and jury Disk Forensics ✔️Ans - The process of acquiring and analyzing information stored on physical storage media, such as computer hard drives, smartphones, GPS systems, and removable media. includes both the recovery of hidden and deleted information and the process of identifying who created a file or message E-mail Forensics ✔️Ans - The study of the source and content of e-mail as evidence. Includes the process of identifying the sender, recipient, date, time, and origination location of an e-mail message. Used to identify harassment, discrimination, or unauthorized activities.Network Forensics ✔️Ans - The process of examining network traffic, including transaction logs and real-time monitoring using sniffers and tracing Internet Forensics ✔️Ans - The process of piecing together where and when a user has been on the Internet.Software Forensics ✔️Ans - The process of examining malicious computer code; also called malware forensics 2 / 3
Live System Forensics ✔️Ans - The process of searching memory in real time, typically for working with compromised hosts or to identify system abuse.Extended data out dynamic random access memory (EDO DRAM) ✔️Ans - Single-cycle EDO has the ability to carry out a complete memory transaction in one clock cycle. Otherwise, each sequential RAM access within the same page takes two clock cycles instead of three, once the page has been selected.Asynchronous dynamic random access memory (ADRAM) ✔️Ans - Not synchronized to the CPU clock Synchronous dynamic random access memory (SDRAM) ✔️Ans - A replacement for EDO Double data rate (DDR) SDRAM ✔️Ans - Later development of SDRAM Read-only memory (ROM) ✔️Ans - This is usually used for instructions embedded in chips and controls how the computer, option cards, peripherals, and other devices operate.Cannot be changed Programmable read-only memory (PROM) ✔️Ans - Can be programmed only once; data is not lost when power is removed.Erasable programmable read-only memory (EPROM) ✔️Ans - Data is not lost when power is removed. Again, this is a technique for storing instructions on chips.Electronically erasable programmable read-only memory (EEPROM) ✔️Ans
- This is how the instructions in your computer's BIOS are stored.
- / 3
Small Computer System Interface (SCSI) ✔️Ans - This has been around for many years, and is particularly popular in high-end servers. Must have a terminator at the end of the chain of devices to work and are limited to 16 chained devices