24. Which of the following is stated within the ISO 27037 standard?
Digital Evidence First Responders should use validated tools.
Software forensics tools must provide a GUI interface.
Software forensics tools must use the Windows OS.
Hardware acquisition tools can only use CRC–32 hashing.
25. In what mode do most write-blockers run?
Enter the appropriate word(s) to complete the statement.
26. The National Software Reference Library has compiled a list of known ___________ for a variety of OSs,
applications, and images.
27. __________ can be platform specific, such as BitLocker, or done with third-party tools, such as Pretty Good Privacy
(PGP) and GNuPG
28. The purpose of having a ______________ function in a forensics tool is to re-create a suspect drive to show what
happened during a crime or incident.
29. The NIST ________________ program establishes guidelines for selecting and using forensics tools.
30. The _____________ utility is designed to be installed on Linux distributions, and can be used to analyze a variety of
different file systems, while also offering the ability to use plugins.
Computer Forensics Tool Testing (CFTT)
National Software Reference Library (NSRL)
password dictionary attack
31. The process of trying every combination of characters—letters, numbers, and special characters typically found on a
keyboard— to find a matching password or passphrase value for an encrypted file
32. The process of pulling relevant data from an image and recovering or reconstructing data fragments; one of the
required functions of digital forensics tools.
33. A hardware device or software program that prevents a computer from writing data to an evidence drive