“Stop! In the Name of the Fourth”
Ctrl + Alt + Defend
Law & Order: Digital Evidence Unit
Hard Drives & Homicide
Passwords, Packets, and Panic
100

This amendment protects people against unreasonable searches and seizures.

What is the Fourth Amendment?

100

This reporting center is a partnership between the FBI and the National White-Collar Crime Center for suspected cybercrime complaints.

What is the IC3?

100

This type of cybercrime investigation involves a single computer or electronic device.

What is a single-scene investigation?

100

If a computer is already off, investigators should do this.

What is leave it off?

100

This process involves anticipating likely threats, calculating their impact, and identifying ways to reduce them.

What is risk analysis?

200

To make sure a search is not unreasonable, officers should usually get one of these from a neutral magistrate.

What is a search warrant? 

200

This agency bills itself as the nation’s “preeminent cryptologic organization.”

What is the NSA?

200

This type of investigation involves more than one computer or device at more than one location.

What is a multiple-scene investigation?

200

If investigators decide to shut down a computer, they should avoid pressing this button.

What is the power button?

200

These checks are one way organizations try to reduce insider threats before hiring employees.

What are background checks?

300

This legal standard is required to obtain a search warrant.

What is probable cause?

300

This federal agency enforces consumer protection laws and antitrust violations.

What is the Federal Trade Commission (FTC)?

300

This type of investigation usually involves the Internet or other networks and often requires outside experts.

What is a network investigation?

300

This process tracks who handled evidence from collection through trial.

What is chain of custody?

300

These devices or systems act like a checkpoint between a network and the Internet.

What are firewalls?

400

This warrantless-search exception allows officers to seize evidence they can clearly see while lawfully present.

What is plain view?

400

This FTC-created database collects identity theft complaints and helps law enforcement develop leads.

What is the Consumer Sentinel?

400

Patrol officers generally should not do this with electronic evidence.

What is collect it?

400

This kind of network is internal to an organization and usually administered by one authority.

What is an intranet?

400

This basic firewall function examines packet header information like IP addresses and port numbers.

What is packet filtering?

500

At the U.S. border, this exception gives the government broader authority to search persons and property.

What is the border search exception?

500

This federal agency, established in 1908, investigates federal crimes and plays a major role in fighting cybercrime.

What is the FBI?

500

Once officers have a warrant, this is their first priority at the scene.

What is officer safety?

500

Investigators may send these to service providers to make sure Internet evidence is kept from being deleted.

What are preservation letters?

500

This firewall technique checks packet sequence numbers and connection status to make sure harmful data is not slipping into a legitimate stream.

What is stateful inspection?

M
e
n
u