Hi folks,

I came across a question, which asks for main categories of evidence. All my research tries, didn't find a markable answer what might be the correct answers. What does not belong to the categories? circumstancial - real - demonstrative or direct evidence.

Any advises?



    Not exactly sure what you mean here.

    For us we basically have 'volatile' evidence - that which is in RAM or in a swap file, Digital, as in log files or Physical, as in floppy disks etc.
    Most of this is not really covered that far in-depth on the exam, but things like Chain of Custody are.
