CIS 359 STUDY Great Stories/cis359study.com CIS 359 STUDY Great Stories/cis359study.com | Page 17

The forensic tool ____ does extensive pre-processing of evidence items that recovers deleted files and extracts e-mail messages. • Question 6 Most digital forensic teams have a prepacked field kit, also known as a(n) ____. • Question 7 The ____ handles computer crimes that are categorized as felonies. • Question 8 Forensic investigators use ____ copying when making a forensic image of a device, which reads a sector (or block; 512 bytes on most devices) from the source drive and writes it to the target drive; this process continues until all sectors on the suspect drive have been copied. • Question 9