SANS FOR500 Questions and Correct
Answers
Analysis Ans: The act of looking at all the individual findings,
including the existence of data, or lack thereof, as well as
associated metadata
DIP Ans: Digital Investigative Plan
What are the three items of a digital investigative plan? Ans: 1.
Basic Background of the investigation for context
2. Clear, detailed explanation of what is being requested
3. Plan of Action
What are the evidence of analysis categories? Ans: 1. User
Communications
© 2025 All rights reserved
, 2 | Page
2. File Download
3. Program Execution
4. File Opening/Creation
5. File Knowledge
6. Physical Location
7. USB Key Usage
8. Account Usage
9. Browser Usage
Arsenal Image Mounter Ans: Forensic Tool Used to mount images
as a drive or physical device for read-only viewing
Volatile Data Ans: Data that will disappear or be destroyed once
the computer system is powered off
© 2025 All rights reserved