1. A forensic investigator at a crime lab is performing a forensic analysis of a
ID: 3756840 • Letter: 1
Question
1. A forensic investigator at a crime lab is performing a forensic analysis of a hard drive that was brought in by state troopers. They make a mistake by using the wrong forensic tool during their forensics examination. What should the investigator do?
a. Document the mistake and workaround the problem.
b. Document the mistake and press on with remaining tasks
c. Disclose the mistake and assess another area of the hard drive
d. Disclose the mistake and preserve the chain of custody
2. When data is collected for a forensic investigation, what order should be followed?
a. Order of volatility
b. Order of risk
c. Order of vulnerability
d. Order of seizure
3. Along with the forensic investigation effort, the man hours and expense should not be tracked since the costs are always justified regardless, of the actual amount involved.
True or false?
4. For what purpose would it be desired to capture the system image?
a. To facilitate security management
b. Check processor performance
c. So memory analysis can be performed later
d. To capture network packets
e. To store the dump file offsite
5. The forensic investigator at a crime lab will be performing a forensic analysis of a hard drive that was brought in by state troopers. What should be done before performing the analysis?
a. Capture data in order of volatility
b. Chain of custody
c. Capture video
d. Capture a system image
Explanation / Answer
1) (B) is the correct option.
The forensic investigator will document the mistake and press on with the remaining tasks.
2) (A) is the correct option.
When data is collected for a forensic investigation the order of volatility is followed to prevent loss of important evidence.
3) is FALSE. The man hours and total expense is tracked for transparency of the system and it also varies based on the situation and importance.
4) (A) is the correct option. To facilitate security management, system image is captured.
5) (A) is the correct option. The forensic investigator should collect all the data precisely before beginning the analysis.
Hope this helps.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.