Assessment
Classroom Discussions
- Under what circumstances is a computer forensics investigator required to conduct an investigation onsite and not be able to remove a computer for analysis back at the lab?
- What are the major challenges associated with removable memory that investigators face?
Multiple-Choice Questions
Which of the following facilitates the communication between a computer’s CPU and hard disks?
- Actuator arm
- ROM chip
- Disk controller
- FireWire
Which of the following is true of a disk clone?
- It is a bootable copy.
- It can be used as a hard drive backup.
- Neither A nor B.
- Both A and B.
Which of the following is true of solid state drives?
- They have no moving parts.
- Files are stored on metal platters.
- It is volatile memory.
- None of the above are true.
Which of the following is volatile memory that is used for processes that are currently running on a computer?
- RAM
- ROM
- Hard disk drive
- Flash
Which of the following refers to two or more disks used in conjunction with one another to provide increased performance and reliability through redundancy?
- RAM
- SCSI
- IDE
- RAID
FireWire is based upon which of the following standards?
- 802.11
- ANSI N42
- IEEE 1394
- ISO 9660
Which of the following memory cards is most likely to be found in Sony electronics?
- Secure Digital Card
- CompactFlash
- MultiMedia Card
- Memory Stick
The reflective surfaces on a CD burned flat by a laser are referred to as which of the following?
- Lands
- Pits
- Mirrors
- Craters
Which of the following is a high-capacity optical disc that can be used to store high-definition video?
- CD
- DVD
- BD
- VCD
Which of the following is a UNIX command that produces a raw data image of a storage medium, like a hard drive or magnetic tape in a forensically sound manner?
- aa
- bb
- cc
- dd
Fill in the Blanks
- Boot ____ is a utility included with Mac OS X 10.6 (Snow Leopard) that enables to user to run Windows operating system on an Intel-based Mac.
- Integrated Drive ____ is a drive interface, connector, and controller, which is largely based on IBM PC standards, for devices like hard disk drives, tape drives, and optical drives.
- ____ ATA is an interface that connects devices, like hard disk drives to host bus adapters.
- A disk ____ is actually one file or a group of files that contain bit-for-bit copies of a hard drive but cannot be used for booting a computer or other operations.
- The Host ____ Area is a region on a hard disk will often contain code associated with the BIOS for booting and recovery purposes.
- ____ collection is a memory management process that removes unused files to make more memory available.
- Fault ____ means that if one component in a system, like a hard disk drive, fails then the system will continue to operate.
- A(n) ____ is a hardware device that allows an individual to read data from a device, like a hard drive, without writing to that device.
- The less reflective surfaces on a CD that have not been burned by a laser are called ____.
- A(n) ____ disk is a thin, flexible, plastic computer storage disc that is housed in a rigid plastic rectangular casing.
Projects
Work with a Dual-Boot System
Find an Apple Mac computer running a dual-boot system, or install Boot Camp and Microsoft Windows on an Apple Mac with Mac OS X currently running. Create standard operating procedures to help computer forensics investigators identify whether a Mac computer is running more than one operating system and determine how to acquire digital evidence from this type of machine.
Identify Changes in Computer Hardware
Write an essay that discusses how computer hardware and memory are likely to be transformed over the next 5 years. Include in your discussion how computer forensics practices will have to change to keep pace with changing technology.
Identify the Use of RAID
Find out how an investigator can identify whether a suspect’s computer is running RAID. How should RAID be forensically examined?
Work with Volatile Memory
Random Access Memory (RAM) can provide an extraordinary amount of evidence. What computer forensics tools can be used to image RAM? Are there any issues with using RAM as a source of evidence in an investigation?
Explain USB Flash Memory
Explain the physical makeup of a USB flash drive. Include in your research how files are stored and organized on this type of storage device.