Professional Documents
Culture Documents
Review 2
Review 2
A. SD cards
B. Thumb drive
C. Hard disk
D. Cell phone
E. Laptop
Which item of evidence is the most volatile?
A. Cell phone
B. USB thumb drive
C. Contents of RAM
D. Laptop hard drive
E. All of the above
Which is the first step done by a forensic
examiner who arrives at a crime scene?
A. Take photographs
B. Label devices
C. Take notes
D. Fill out Chain of Custody form
E. Remove extra people
Joe is making a clone of the evidence drive onto
a target drive. Which of these is not a good
practice?
A. Deleted data
B. Hiberfil
C. Page file
D. Registry
E. Metadata
Which type of data must be reconstructed with
file carving?
A. Thumbnails
B. MRU list
C. Restore points
D. Deleted data
E. Metadata
Where is the identity of the last-logged-in user
stored?
A. MRU list
B. Hiberfil
C. Page file
D. Registry
E. Metadata
Where is the Modified timestamp for a file
stored?
A. MRU list
B. Hiberfil
C. Page file
D. Registry
E. Metadata