Warrants, Investigations, and Court (Ch5)
Crime Scenes and Evidence Storage (Ch5)
Surprise Me! (Ch5 and Ch6)
Disk Drives (Ch6)
File Systems and Windows Registry (Ch6)
100

A statement made by someone not present at the event.

What is hearsay?

100

A storage device that has a lifespan of over 1,000 years.

What is M-Disc?

100

Data that can identify someone, like name, address, or SSN.

What is personal identifiable information (PII)?

100

The HDD component that reads and writes data to the disk drive.

What is the head or read/write head?

100

A structure that provides an OS with a roadmap to data on a disk

What is a file system?

200

Wording in a warrant that restricts what can be seized, separating evidence from unrelated data.

What is a limiting phrase?

200

How often evidence must be kept under surveillance while in transport.

What is at all times?

200

A covert surveillance tool that monitors network data sent to and from the employee’s device in real time.

What is a sniffer?

200

The small unused space between partitions.

What is a partition gap?

200

The hierarchical database containing system and user information.

What is Windows registry?

300

Objects seen by an officer in a place they have the right to be can be seized without a warrant.

What is the plain view doctrine?

300

A covert surveillance tool that must be configured with a firewall to avoid detection.

What is a keylogger?

300

Files created by a person, like spreadsheets or Word documents.

What are computer-stored digital records?

300

The location of each partition volume's boot sector (first sector storing file system and boot info).

What is sector 0?

300

This NTFS feature records transactions before the system carries them out to help prevent data loss.

What is journaling?

400

What employees can assume if there are no warning banners or company-defined policies present when using company resources.

What is an expectation of privacy?

400

Motivation that causes professional personnel to examine an incident or crime scene to see what happened

What is professional curiosity?

400

A file structure database that is usually located on the disk's outermost track.

What is a file allocation table (FAT)?

400

The disk partition program that stores disk sizes and locations for older devices and can be up to 2.2 TB in size.

What is the Master Boot Record (MBR)?

400

The Windows registry file that contains current logged-on user info.

What is HKEY_USERS?

500

What an investigator becomes if they find evidence of a crime while investigating a policy violation and do not get a search warrant. 

What is an agent of law enforcement? 

500

The process of taking photos, videos, and recording details of a suspect device and environment. 

What is cataloging a crime scene?

500

The Windows registry file path that stores a data file containing the computer's security settings. 

What is Windows\system32\config\Security.dat

500

Groups tracks so the inner and outer tracks store the same amount of data.

What is a zone bit recording (ZBR)?

500

The Windows file that stores information about computers in hibernation.

What is hiberfile.sys?

M
e
n
u