Skip to main content

Test Bank For E-Discovery An Introduction to Digital Evidence, 1st Edition

Page 1

Chapter 01 - Introduction to E-discovery and Digital Evidence TRUE/FALSE 1. E-discovery is the use of advanced electronic surveillance to catch criminals in the act. ANS: F

PTS: 1

REF: 2

2. Metadata is a legal term that refers to the actual information being retrieved. ANS: F

PTS: 1

REF: 4

3. Cloud computing is a model in which computing resources are hosted remotely. ANS: T

PTS: 1

REF: 7

4. In general, states’ rules regarding ESI can be more lenient than federal rules. ANS: F

PTS: 1

REF: 16

5. The Sedona Canada principles and the Ontario checklist for preparing a discovery plan are part of Canadian procedural law. ANS: T

PTS: 1

REF: 19

MULTIPLE CHOICE 1. Which of the following is true about E-discovery? a. it can be thought of as data mining b. it consists of hard copies of court documents c. it does not include data found on cellular phones d. it is valid in civil cases, but not in criminal cases ANS: A

PTS: 1

REF: 2

2. Which of the following is true about digital forensics? a. device forensics focuses on network intrusion b. a MAC time tells a digital forensics expert the hardware address of a computer c. network forensics experts consider e-discovery a part of their job d. e-discovery can be considered a subset of digital forensics ANS: C

PTS: 1

REF: 2

3. The process of retrieving evidence from the data of an encrypted hard drive would be considered the job of which of the following? a. network forensics expert c. ESI administrator b. e-discovery expert d. device forensics expert ANS: D

PTS: 1

REF: 2

4. Which of the following is NOT true about digital evidence? a. it can pertain to a civil or criminal complaint b. it is only found on desktop computers


c. it must be acquired by following specific procedures d. e-mail is an example ANS: B

PTS: 1

REF: 4

5. Which of the following is an example of metadata? a. a paragraph in a printed document c. GPS data for a photo b. words in an electronic document d. DNA extracted from blood ANS: C

PTS: 1

REF: 4

6. Where should you look if you want to find what camera was used to take a photograph? a. on the back of the photo file c. on a hardcopy of the photo b. in the EXIF header d. in the jpg pixels ANS: B

PTS: 1

REF: 5

7. Why might you want to use the AccessData Forensic Toolkit? a. to view document metadata c. to listen in on cell phone transmissions b. to examine blood evidence d. to capture network data ANS: A

PTS: 1

REF: 6

8. In which computer and networking model are client software, data, and computing resources hosted remotely, so client computers and servers don’t need to support as many on-site resources? a. WAN network c. Cloud computing b. Internetwork model d. Mainframe processing ANS: C

PTS: 1

REF: 7

9. Which of the following is NOT a service model defined by NIST? a. SaaS c. IaaS b. PaaS d. NaaS ANS: D

PTS: 1

REF: 7

10. Which of the following is NOT a cloud deployment method defined by NIST? a. internal c. hybrid b. private d. public ANS: A

PTS: 1

REF: 7

11. With which service model do customers select an OS and install their own applications? a. SaaS c. NaaS b. PaaS d. IaaS ANS: B

PTS: 1

REF: 7

12. Which cloud deployment method is considered the most secure? a. public c. internal b. hybrid d. private ANS: D

PTS: 1

REF: 7

13. What must be followed to ensure that evidence has not been tampered with or altered? a. search warrants c. subpoenas b. chain of custody d. requests for production


ANS: B

PTS: 1

REF: 8

14. When examining digital evidence on a device, what is used to prevent data from being copied back to the evidence item inadvertently? a. write blocker c. deduplication b. live acquisitions d. forensic imaging ANS: A

PTS: 1

REF: 9

15. Which set of rules was established in 1938 for resolving issues or legal matters in civil cases at the federal level? a. FRCP c. FRErP b. FRCrP d. FRE ANS: A

PTS: 1

REF: 10

16. Which set of rules applies to all evidence presented in court for both civil and criminal cases? a. FRCP c. FRErP b. FRCrP d. FRE ANS: D

PTS: 1

REF: 11

17. Which Federal Rule of Evidence is relevant to the admissibility of e-mail messages? a. Limited Admissibility c. Hearsay b. Relevancy and Its Limits d. Opinions and Expert Testimony ANS: C

PTS: 1

REF: 11

18. Which of the following were created by a group of lawyers and other professionals as guidelines for handling electronic documents? a. Federal Rules of Evidence c. Advisory Committee on Civil Rules b. Sedona Principles d. UN Model Law ANS: B

PTS: 1

REF: 12

19. What type of software can be used to index the text contained in scanned pictures of documents? a. TIFF c. OCR b. PDF d. ESI ANS: C

PTS: 1

REF: 14

20. Which of the following was developed as the result of burgeoning e-commerce in the 1990s, focused on civil procedures, and has been a basis for e-discovery worldwide? a. UN Model Law c. Canadian Rules of Civil Procedure b. European Corporate Laws d. Sedona Canada Principles ANS: A

PTS: 1

REF: 16

COMPLETION 1. E-Discovery can be thought of as data _________ to gather information for use in legal proceedings. ANS: mining PTS: 1

REF: 2


2. Dropbox is an example of the ___________ cloud service model. ANS: SaaS PTS: 1

REF: 7

3. With a __________ cloud, a person’s files are on the same physical machine as another person’s or organization’s files. ANS: public PTS: 1

REF: 7

4. In the context of e-discovery, ____________ evidence is called ESI. ANS: digital PTS: 1

REF: 12

5. Replacing paper documents with electronic documents in PDF or TIFF format is an example of good ___________ management. ANS: ESI PTS: 1

REF: 14

MATCHING Match each item with the description below. a. chain of custody b. data mining c. digital evidence d. digital forensics e. e-discovery

f. g. h. i. j.

ESI FRCrP MAC times native file OCR

1. any evidence that’s stored or transmitted electronically or in a digital format 2. a software method of scanning a picture and converting the characters to text 3. rules created by the U.S. Supreme Court to ensure that defendants’ constitutionally guaranteed rights are protected in federal court cases 4. the path evidence takes from the time the investigator obtains it until the case goes to court or is dismissed 5. gathering ESI for use in litigation 6. metadata that specifies dates and times that a file was modified, accessed, and created 7. a method used to gather information about customers or vendors by culling ESI 8. a file in the originating application’s format 9. any information stored electronically or in a digital format 10. the application of traditional forensics procedures to acquiring computer evidence 1. ANS: C 2. ANS: J 3. ANS: G

PTS: 1 PTS: 1 PTS: 1

REF: 20 | 3 REF: 21 | 14 REF: 20 | 11


4. 5. 6. 7. 8. 9. 10.

ANS: A ANS: E ANS: H ANS: B ANS: I ANS: F ANS: D

PTS: PTS: PTS: PTS: PTS: PTS: PTS:

1 1 1 1 1 1 1

REF: REF: REF: REF: REF: REF: REF:

20 | 8 20 | 2 21 | 2 20 | 2 21 | 15 20 | 2 20 | 2

SHORT ANSWER 1. Describe e-discovery in terms of data mining. ANS: One way to look at e-discovery is as a form of data mining, a method companies use to gather information about customers or vendors. E-discovery can be thought of as data mining to gather information for use in legal proceedings. PTS: 1

REF: 2

2. What are the two specialties of digital forensics? ANS: The field of digital forensics is divided into two specialties: device forensics and network forensics. In device forensics, the expert retrieves items such as existing files, deleted files, hidden files, encrypted data, and more. Network forensics deals with network intrusion and hackers. In these cases, the focus is on finding out how intruders got into the network and making sure they’re locked out so that business can continue. PTS: 1

REF: 2

3. What is a difference between e-discovery and digital forensics? ANS: A key difference between e-discovery and digital forensics is that in digital forensics, investigators are typically looking for incriminating or exculpatory evidence in a criminal case or an investigation of a corporate policy violation. In e-discovery, Company A asks Company B for data pertaining to a litigation matter. PTS: 1

REF: 2

4. Describe digital evidence. What are some sources of digital evidence? ANS: Digital evidence is data or files in digital format that pertain to a civil or criminal complaint. ESI and electronically transmitted information fall under this definition. Both can be used in court as evidence in much the same manner as gunshot residue or DNA gathered from a bloodstain. In any home or office, many common items contain digital evidence. Toaster ovens, cameras, watches, fax machines, copiers, and phones—all contain processors or electronic storage devices. PTS: 1

REF: 3-4

5. Discuss the difference between data and metadata providing examples.


ANS: Data is the actual information being retrieved, such as a letter or document. Metadata is information about that data—that is, data about data. For example, when people use social media sites to post photos, the metadata in a picture file can tell investigators the type of camera used, the date the photo was taken, and the GPS coordinates where the photo was taken. PTS: 1

REF: 4

6. Describe software as a service (SaaS). Provide an example. ANS: SaaS refers to applications provided for customers. Typically, these applications are for users who want the convenience of accessing their files from any location and sharing them with any location. People can access their files via the cloud and make changes with SaaS applications. Two common SaaS providers are Dropbox and Google Docs. PTS: 1

REF: 7

7. How does the cloud affect e-discovery? ANS: If an employee is in Los Angeles but the data she’s accessing is stored in London, New York City, Bangkok, and Cape Town, which location’s laws apply when collecting e-discovery evidence? Does it depend on where the employee is located or where the evidence is located? PTS: 1

REF: 7

8. What is the importance of chain of custody? ANS: How digital evidence is acquired affects the way it’s presented and accepted in court. In civil cases, in which one company is suing another, evidence is acquired by issuing a request for production, meaning one company requests physical or electronic documents or other information, and the second company produces them. In criminal cases, the procedure is different. It requires strict adherence to chain of custody, use of search warrants, subpoenas, and so forth. The objective of a strict chain of custody is to make sure evidence hasn’t been tampered with or altered in the process. PTS: 1

REF: 8

9. How does the volume of information involved in a case affect the e-discovery process? How can the impact be reduced? ANS: In selecting software, a company involved in e-discovery has to consider cost and time. Large multinational corporations can afford expensive packages to handle e-discovery tasks, but small and medium firms that have the same need for e-discovery tools might not have the budget. Freeware and shareware products can be used reliably, but they might be difficult to learn, and technical support might not be readily available. One way to reduce the cost and time of an investigation substantially is to ask ―Which information is needed to prove a case?‖ Is it in an e-mail from a particular two-month period? Is it in documents containing a certain word or phrase? Instead of requesting ―everything,‖ strive to be more specific and narrow the focus of what you’re searching for.


PTS: 1

REF: 10

10. How has the introduction of digital evidence changed the FRE, if at all? ANS: The introduction of digital evidence hasn’t changed the FRE extensively. It does, however, add many new interpretations of old rules. The hearsay rule is one example. Text messages and e-mails might prove the recipient had been told something; however, these messages can’t prove the information’s veracity. PTS: 1

REF:

12Chapter 02 - A Brief History of E-discovery

TRUE/FALSE 1. ARPANET was the precursor to the Internet. ANS: T

PTS: 1

REF: 28

2. Prior to the explosion of the Internet, most hackers were employees of the organizations they hacked into. ANS: T

PTS: 1

REF: 30

3. Civil attorneys tend to rely on OS metadata rather than metadata embedded in documents. ANS: F

PTS: 1

REF: 36

4. In the EDRM, the collection stage comes before the preservation stage. ANS: F

PTS: 1

REF: 42

5. Arthur Andersen was charged with obstruction of justice after destroying documents related to its audit of Enron. ANS: T

PTS: 1

REF: 44

MULTIPLE CHOICE 1. Which of the following happened during the mid-1980’s? a. companies began using mainframes b. the Internet backbone was developed c. government made use of the ARPANET d. the U.S. PATRIOT Act was passed ANS: B

PTS: 1

REF: 28

2. Which law came into effect in 1986 to address the growing problem of computers being hacked? a. CADAA c. CFAA b. U.S. PATRIOT ACT d. NIIPA ANS: C

PTS: 1

REF: 28


Turn static files into dynamic content formats.

Create a flipbook
Test Bank For E-Discovery An Introduction to Digital Evidence, 1st Edition by AnswerDone - Issuu