Exam Essentials
Forensic investigations require a complete forensic toolkit. Forensic toolkits include digital forensics workstations, forensic software, write blockers, wiped drives, cables and drive adapters, cameras, chain-of-custody forms, incident response forms and plans, and escalation lists. Law enforcement investigations may include specialized items like tamper-proof seals and crime scene tape to restrict access to the scene or devices.
Forensic software provides specialized capabilities for investigations. Forensic tools include analysis utilities that can provide timelines; file validation; filesystem analysis for changes, deletions, and other details; log file viewing; and other analysis. Key data acquisition capabilities include dead, or offline system, cloning and validation via hashing, chain-of-custody and activity logging, and live system imaging. Password cracking and recovery, as well as the ability to decrypt common types of encrypted files, are necessary for many...