D4 · Operations

What is digital forensics?

Digital forensics identifies, preserves, analyzes, and presents digital evidence — for incident investigations, legal proceedings, or internal disciplinary matters.
Four phases: Collection (with write blockers, hashing), Examination (extract relevant data), Analysis (draw conclusions), Reporting (document findings). ACPO principles: don't modify original, document all actions, follow lawful process. Evidence must be legally obtained and properly handled.
← Back to Glossary Practice Questions →