AccessData Certified Examiner (ACE) โ Questions and Answers
Question 1: In forensic documentation, 'artifacts' should be described as:
- Physical objects only
- Conclusive proof of user actions
- Always reliable indicators of intent
- Remnants of system activity that may indicate user behavior (Correct answer)
Correct answer: Remnants of system activity that may indicate user behavior
Digital artifacts are remnants of system or user activity that may indicate behavior, but their interpretation must be qualified and not overstated.
Question 2: What is the primary legal concern when a forensic examiner acquires a forensic image of an employee's personal smartphone that was used for both business and personal purposes?
- Violation of PCI DSS storage requirements
- Fourth Amendment and employee privacy rights under state law (Correct answer)
- Violation of the Wiretap Act only
- OSHA workplace safety regulations
Correct answer: Fourth Amendment and employee privacy rights under state law
BYOD investigations raise Fourth Amendment issues and state privacy law concerns because employees retain a reasonable expectation of privacy in personal data on their devices.
Question 3: What is a forensic image in digital evidence acquisition?
- A manually edited set of files
- An exact copy of a digital device (Correct answer)
- A compressed version of select data
- A summary report of important files
Correct answer: An exact copy of a digital device
A forensic image is a bit-for-bit, sector-by-sector duplicate of a digital storage device, capturing all data including active files, deleted files, and unallocated space. This exact copy serves as the working evidence for analysis, ensuring the original device remains untouched and its integrity preserved. It is fundamental for maintaining the authenticity and admissibility of digital evidence.
Question 4: Which step must be performed before disconnecting a running server to prevent evidence loss?
- Document and capture volatile system state including running processes and network connections (Correct answer)
- Run CHKDSK to verify disk integrity
- Defragment the file system
- Disable all user accounts on the system
Correct answer: Document and capture volatile system state including running processes and network connections
Before powering down a running server, examiners must document volatile evidence (processes, connections, logged-in users) that will not survive a shutdown.
Question 5: In digital forensics, what does 'chain of custody' documentation ensure?
- The suspect cannot access the evidence during trial
- The evidence is encrypted at rest
- A verifiable, chronological record of who handled evidence, when, and under what conditions (Correct answer)
- Automatic backup of all case files to a secure server
Correct answer: A verifiable, chronological record of who handled evidence, when, and under what conditions
Chain of custody logs every transfer, access, and storage condition of evidence, making it admissible in court by demonstrating it was not tampered with.
Question 6: How does FTK analyze web browsing history from a Windows evidence image?
- By examining only the Windows Event Log for browser activity
- By parsing browser artifact databases such as Chrome and Firefox SQLite files and IE index.dat to extract visited URLs and timestamps (Correct answer)
- By running keyword searches on the browser executable only
- By reviewing only the browser's LNK shortcut files
Correct answer: By parsing browser artifact databases such as Chrome and Firefox SQLite files and IE index.dat to extract visited URLs and timestamps
FTK parses browser-specific artifact files (SQLite databases for Chrome/Firefox, index.dat for IE) to reconstruct browsing history with URLs and timestamps.
Question 7: What does 'slack space' analysis reveal in a forensic examination?
- The volume shadow copy history
- Remnants of previously stored data between the end of a file and the end of its allocated cluster (Correct answer)
- The amount of free disk space available
- The swap file contents from RAM
Correct answer: Remnants of previously stored data between the end of a file and the end of its allocated cluster
Slack space is the unused area between a file's logical end and the end of its last allocated cluster, which may contain fragments of previously deleted data.
Question 8: What is the primary reason an examiner creates both MD5 and SHA-1 hashes for a forensic image?
- Courts require both algorithms by statute
- MD5 verifies file names while SHA-1 verifies content
- Dual hashing provides defense against hash collision attacks and strengthens integrity proof (Correct answer)
- FTK only accepts dual-hash images
Correct answer: Dual hashing provides defense against hash collision attacks and strengthens integrity proof
Using two independent algorithms makes it computationally infeasible for an attacker to craft a collision that matches both, strengthening admissibility arguments.
Question 9: What is 'anti-forensics' in the context of digital investigations?
- The process of verifying the integrity of collected evidence
- Techniques used to destroy, conceal, or manipulate digital evidence to impede forensic investigations (Correct answer)
- Encrypting forensic case files to maintain confidentiality
- Writing court-admissible forensic examination reports
Correct answer: Techniques used to destroy, conceal, or manipulate digital evidence to impede forensic investigations
Anti-forensics encompasses methods such as file wiping, timestamp alteration, steganography, and encryption used to obstruct or invalidate forensic analysis.
Question 10: During a network intrusion investigation, an examiner finds $MFT records with a $STANDARD_INFORMATION timestamp earlier than the $FILE_NAME timestamp. What does this most likely indicate?
- Normal file system behavior during defragmentation
- A corrupted MFT record requiring repair
- Timestomping โ deliberate manipulation of $STANDARD_INFORMATION timestamps to obscure file activity (Correct answer)
- The file was compressed by NTFS
Correct answer: Timestomping โ deliberate manipulation of $STANDARD_INFORMATION timestamps to obscure file activity
Timestomping tools modify $STANDARD_INFORMATION timestamps (visible in Windows Explorer) but often fail to alter $FILE_NAME timestamps, creating a detectable inconsistency.
Question 11: What does Windows Security Event ID 4625 indicate?
- A user account was created
- An audit policy was changed
- A failed logon attempt occurred (Correct answer)
- A privileged service was started
Correct answer: A failed logon attempt occurred
Event ID 4625 is logged whenever an account fails to authenticate, which is critical for detecting brute force attacks and unauthorized access attempts.
Question 12: What is a rule-based (or hybrid) attack in PRTK?
- Combining two dictionary files into a single wordlist
- Using known plaintext to derive the encryption key
- Splitting a brute force attack across multiple processors
- Applying transformation rules (e.g., capitalize, append numbers) to dictionary words to generate candidates (Correct answer)
Correct answer: Applying transformation rules (e.g., capitalize, append numbers) to dictionary words to generate candidates
A rule-based attack applies mutations โ such as capitalization, substitution, or appending digits โ to dictionary entries to cover predictable password patterns.
Question 13: When using FTK Imager's 'Capture Memory' function, what type of file is created that an examiner would later load into a memory analysis tool?
- An E01 EnCase evidence file
- A hibernation file (hiberfil.sys) clone
- A raw .mem or .dmp memory dump file (Correct answer)
- A .vmem virtual machine memory snapshot
Correct answer: A raw .mem or .dmp memory dump file
FTK Imager's Capture Memory function creates a raw memory dump file (.mem or .dmp) containing the full contents of physical RAM at capture time.
Question 14: What does the Master Boot Record (MBR) contain that is forensically significant?
- Prefetch execution data
- Partition table, boot code, and disk signature (Correct answer)
- File system journal entries
- User account hashes
Correct answer: Partition table, boot code, and disk signature
The MBR contains the bootstrap code, the partition table defining disk layout, and a unique disk signatureโall relevant to understanding disk structure.
Question 15: What is the primary legal consideration in digital forensics?
- Modifying evidence for better clarity
- Altering timestamps for accuracy
- Ensuring evidence is admissible in court (Correct answer)
- Deleting irrelevant data before analysis
Correct answer: Ensuring evidence is admissible in court
The primary legal consideration in digital forensics is ensuring that collected evidence is admissible in court. This requires strict adherence to legal standards and forensic procedures to maintain the evidence's integrity, authenticity, and chain of custody. If evidence is not admissible, it cannot be used to prove facts in a legal proceeding, rendering the entire forensic effort ineffective.
Question 16: Why should forensic images always be stored on media separate from the examiner's working copy?
- To speed up hash verification
- To preserve the original evidence image unaltered while analysis is done on the copy (Correct answer)
- To comply with NTFS file size limitations
- To save storage space through deduplication
Correct answer: To preserve the original evidence image unaltered while analysis is done on the copy
Keeping the original image untouched ensures that evidence integrity is maintained and the original can be re-examined if the working copy is corrupted.
Question 17: What should be the first action when a new regulation is enacted that affects your practice?
- Review the regulation, assess its impact, and develop an implementation plan (Correct answer)
- Wait for enforcement before making changes
- Assume existing procedures already comply
- Delegate review to the newest team member
Correct answer: Review the regulation, assess its impact, and develop an implementation plan
When new regulations are enacted, professionals should promptly review them, assess their impact on current practices, and develop a structured implementation plan.
Question 18: What is the forensic significance of a password found in the Windows Credential Manager or DPAPI-protected storage?
- It must be decrypted separately using a different DPAPI key before it can be used
- It is stored in an irreversible hash format and cannot be recovered in plaintext
- It only applies to domain accounts and is irrelevant for local account investigations
- It may provide the actual password used for encrypted files, websites, or network shares without requiring cracking (Correct answer)
Correct answer: It may provide the actual password used for encrypted files, websites, or network shares without requiring cracking
Windows Credential Manager and DPAPI often store passwords in a form recoverable with the user's account credentials, providing plaintext passwords that can directly unlock encrypted resources.
Question 19: GPU acceleration in password cracking provides a significant advantage primarily because GPUs:
- Can store more dictionary entries in cache
- Contain thousands of cores optimized for parallel mathematical operations (Correct answer)
- Operate at higher clock speeds than modern CPUs
- Have faster memory access than CPUs
Correct answer: Contain thousands of cores optimized for parallel mathematical operations
GPUs contain thousands of small cores designed for parallel processing, allowing them to compute millions of hash comparisons simultaneously โ far exceeding CPU performance for cracking tasks.
Question 20: What security mechanism makes rainbow table attacks significantly less effective?
- Using a longer hashing algorithm
- Salting the password before hashing (Correct answer)
- Encrypting the hash output
- Storing passwords in base64 encoding
Correct answer: Salting the password before hashing
Salting adds a unique random value to each password before hashing, ensuring identical passwords produce different hashes and invalidating precomputed rainbow tables.
Question 21: A trainer posts a client's dramatic body transformation photo on social media without asking. This violates which ethical principle?
- Confidentiality (Correct answer)
- Competence
- Beneficence
- Fidelity
Correct answer: Confidentiality
Sharing identifiable client information or images without written consent violates client confidentiality.
Question 22: An examiner receives a hard drive with a damaged partition table. Which FTK Imager feature allows imaging despite this condition?
- Verify Drive/Image
- Mount Image to Drive Letter
- Create Disk Image with custom sector range (Correct answer)
- Add Evidence Item โ Physical Drive
Correct answer: Create Disk Image with custom sector range
Specifying a custom sector range lets the examiner image readable sectors even when the partition table is corrupt or missing.
Question 23: An examiner is hired by a plaintiff in a civil case. During examination they find evidence clearly helpful to the defendant. Ethically, the examiner should:
- Exclude the evidence from the report to protect the client
- Report all findings accurately to the retaining attorney regardless of who they benefit (Correct answer)
- Destroy the evidence to prevent disclosure
- Notify the defendant's counsel directly
Correct answer: Report all findings accurately to the retaining attorney regardless of who they benefit
Forensic examiners are obligated to report all findings truthfully; withholding contrary evidence violates professional ethics and may constitute fraud.
Question 24: What is the purpose of volatility analysis in digital forensics?
- Convert encrypted files to plain text
- Delete unnecessary log files
- Modify file timestamps
- Recover memory-based artifacts (Correct answer)
Correct answer: Recover memory-based artifacts
Volatility analysis in digital forensics focuses on examining the contents of a computer's random access memory (RAM) to recover volatile data. This includes running processes, open network connections, loaded drivers, and cryptographic keys, which are lost once the system is powered off. Analyzing these memory-based artifacts can provide crucial insights into system activity and malware presence that are not found on persistent storage.
Question 25: What type of traffic does a packet sniffer capture during network forensic analysis?
- Only HTTPS-encrypted web traffic streams
- Only wireless beacon and management frames
- Exclusively DNS query and response messages
- Raw network packets traversing the monitored network interface (Correct answer)
Correct answer: Raw network packets traversing the monitored network interface
A packet sniffer captures all raw packets at the network interface level, providing complete visibility into communications regardless of protocol.
Question 26: What does FTK's 'live search' capability allow an examiner to do?
- Search for keywords or patterns across evidence data without waiting for full indexing (Correct answer)
- Remotely connect to and search a live suspect computer
- Automatically update FTK's case database in real time
- Synchronize evidence with a cloud repository
Correct answer: Search for keywords or patterns across evidence data without waiting for full indexing
FTK's live search lets examiners run keyword or regex searches directly against evidence data immediately without requiring a completed index.
Question 27: What is the forensic purpose of analyzing the Windows Recycle Bin artifacts ($I and $R files) on a NTFS volume?
- To recover the contents of deleted RAM
- To identify USB devices previously connected
- To determine the original file path, deletion time, and recover the content of deleted files (Correct answer)
- To view network connection history
Correct answer: To determine the original file path, deletion time, and recover the content of deleted files
$I files store metadata (original path and deletion timestamp) while $R files store the actual deleted file content, together providing complete evidence of deliberate file deletion.
Question 28: An investigator is responding to a ransomware incident. Which evidence should be collected BEFORE isolating the infected system from the network?
- Installed software registry keys
- File system directory listings
- Network connections, active processes, and running memory to identify encryption keys (Correct answer)
- Email archive PST files
Correct answer: Network connections, active processes, and running memory to identify encryption keys
Active network connections and RAM may contain the ransomware's encryption keys or C2 communication data that disappears upon network isolation or shutdown.
Question 29: When a forensic examiner works on a case involving a publicly traded company, which obligation does SOX impose regarding electronic records retention?
- Financial records must be retained for 10 years
- All records must be kept for 3 years
- Audit work papers must be retained for 7 years (Correct answer)
- Email must be preserved for 5 years
Correct answer: Audit work papers must be retained for 7 years
SOX requires auditors to retain audit work papers and related records for 7 years after completing the audit.
Question 30: Which Windows registry location stores previously connected wireless (Wi-Fi) network profiles?
- HKLM\SAM\SAM\Domains\Account\Users
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles and WLAN event logs (Correct answer)
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
- HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Correct answer: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles and WLAN event logs
Windows stores Wi-Fi network history in the NetworkList registry key and WLAN AutoConfig event logs, which can reveal location history based on network associations.
Question 31: A suspect's laptop is found with BitLocker encryption enabled and running. What is the FIRST action an examiner should take?
- Attach a write-blocker and image the disk
- Boot into a live Linux environment
- Immediately pull the power cord
- Acquire a RAM dump to capture the encryption key (Correct answer)
Correct answer: Acquire a RAM dump to capture the encryption key
Capturing a RAM dump first recovers the BitLocker key from memory, enabling decryption; powering off would destroy the key.
Question 32: Which of the following is MOST consistent with continuous quality improvement (CQI) in personal training?
- Using the same programming system for 10 years without updates
- Regularly seeking client feedback, reviewing outcomes, and refining practices (Correct answer)
- Delegating all program adjustments to the facility manager
- Maintaining identical session structures regardless of client progress
Correct answer: Regularly seeking client feedback, reviewing outcomes, and refining practices
CQI is an ongoing cycle of feedback, outcome review, and practice refinement rather than a static approach to service delivery.
Question 33: What is the purpose of feedback in ACORD Certified Expert professional development?
- To provide constructive guidance for improvement (Correct answer)
- To justify termination
- To criticize mistakes only
- To rank employees
Correct answer: To provide constructive guidance for improvement
Constructive feedback identifies areas of strength and opportunities for improvement, supporting ongoing professional growth.
Question 34: When examining a BitLocker-encrypted drive, which of the following is the most examiner-friendly recovery method if the recovery key is unavailable?
- Imaging the encrypted volume and processing it directly in FTK
- Disabling BitLocker through the Windows RE environment
- Searching the Microsoft account or Active Directory for the stored BitLocker Recovery Key (Correct answer)
- Running a GPU-accelerated brute force attack against the volume header
Correct answer: Searching the Microsoft account or Active Directory for the stored BitLocker Recovery Key
BitLocker recovery keys are automatically backed up to Microsoft accounts or Active Directory, making this the fastest and most reliable recovery path for examiners.
Question 35: What does analyzing DNS artifacts during network forensics help an investigator determine?
- The physical location of a network switch
- The encryption keys used in SSL/TLS sessions
- The hardware MAC addresses of all devices on a subnet
- Which domain names a system resolved, revealing connections to websites, C2 servers, or exfiltration targets (Correct answer)
Correct answer: Which domain names a system resolved, revealing connections to websites, C2 servers, or exfiltration targets
DNS resolution records show which domain names a host looked up, helping establish communications with malicious domains, C2 infrastructure, or unauthorized services.
Question 36: In the context of AccessData FTK, what does the 'Cerberus' malware analysis module provide?
- Automated behavioral and static analysis of suspect executables to detect malware characteristics (Correct answer)
- Real-time monitoring of running processes
- Brute-force decryption of encrypted containers
- Network traffic decryption
Correct answer: Automated behavioral and static analysis of suspect executables to detect malware characteristics
Cerberus performs automated malware triage on executable files using static analysis (PE structure, imports, strings) and behavioral indicators without requiring detonation.
Question 37: Which Windows Security Event ID indicates a successful user account logon?
- Event ID 1102
- Event ID 4624 (Correct answer)
- Event ID 4625
- Event ID 4688
Correct answer: Event ID 4624
Windows Security Event ID 4624 is logged each time a user account successfully authenticates and establishes a logon session.
Question 38: Which tool is used to recover deleted files in forensic investigations?
- Notepad++
- Google Sheets
- Autopsy (Correct answer)
- Wireshark
Correct answer: Autopsy
Autopsy is a popular open-source digital forensics platform that includes robust capabilities for recovering deleted files. It allows investigators to analyze file systems, identify and carve out deleted data, and reconstruct file fragments. This functionality is crucial for uncovering evidence that suspects may have attempted to conceal by deleting it.
Question 39: When acquiring evidence from a live system, which method best preserves volatile memory that would be lost on shutdown?
- Perform a RAM dump before any disk imaging (Correct answer)
- Create a static disk image only
- Power off immediately and image the drive
- Clone the hard drive using a write-blocker
Correct answer: Perform a RAM dump before any disk imaging
RAM dump captures volatile memory contents (running processes, encryption keys, network connections) that are destroyed when power is removed.
Question 40: According to the order of volatility, which data source must be collected FIRST at a live scene?
- Log files stored on disk
- Backup tapes in the server room
- External hard drive image
- RAM/memory contents (Correct answer)
Correct answer: RAM/memory contents
RAM is the most volatile data source and must be captured before any other action, as it is destroyed immediately when the system loses power.
Question 41: What is write-blocking and why is it critical during forensic acquisition?
- It prevents any write commands from reaching the evidence drive, preserving its original state (Correct answer)
- It speeds up read operations by caching sectors
- It encrypts the forensic image during transfer
- It compresses data during imaging to save space
Correct answer: It prevents any write commands from reaching the evidence drive, preserving its original state
Write-blockers intercept and discard write commands at the hardware or software level, ensuring no data on the evidence drive is modified during imaging.
Question 42: Which U.S. regulation requires financial institutions to file a Suspicious Activity Report (SAR) within 30 days of detecting a transaction that may involve money laundering, and is relevant when forensic findings reveal illicit financial flows?
- Sarbanes-Oxley Act
- Fair Credit Reporting Act
- Dodd-Frank Act
- Bank Secrecy Act (BSA) / FinCEN regulations (Correct answer)
Correct answer: Bank Secrecy Act (BSA) / FinCEN regulations
The Bank Secrecy Act, enforced through FinCEN regulations, requires financial institutions to file SARs within 30 days of detecting suspicious transactions that may involve money laundering or other crimes.
Question 43: Which file system artifact is MOST useful for proving a USB drive was connected to a Windows system even if the drive has been removed?
- USBSTOR registry keys and Windows Event Log entries on the host (Correct answer)
- BitLocker metadata on the USB drive
- The USB drive's file allocation table
- $MFT records from the USB drive
Correct answer: USBSTOR registry keys and Windows Event Log entries on the host
USBSTOR registry entries and Event Log records on the host system log device connection details (serial number, timestamps) independent of the physical USB drive.
Question 44: When FTK identifies an encrypted file during processing, what is the recommended first step before attempting password recovery?
- Immediately begin a brute force attack
- Check if the password or key material exists elsewhere in the image (e.g., swap file, registry) (Correct answer)
- Export the file and use a third-party tool
- Mark the file as inaccessible and note it in the report
Correct answer: Check if the password or key material exists elsewhere in the image (e.g., swap file, registry)
Key material, passwords, or encryption artifacts may exist in other areas of the image such as unallocated space, the registry, or hibernation/swap files, providing a faster path than cracking.
Question 45: Why is the Windows pagefile (pagefile.sys) forensically significant?
- It holds memory pages swapped from RAM to disk, potentially including process data, fragments of documents, and passwords (Correct answer)
- It contains the user's complete browsing history
- It records a log of all file access operations
- It stores encrypted copies of the SAM database
Correct answer: It holds memory pages swapped from RAM to disk, potentially including process data, fragments of documents, and passwords
The pagefile contains RAM pages that were swapped to disk, preserving volatile data fragments even after the system is shut down.
Question 46: A suspect's password-protected ZIP archive uses PKZIP 2.0 (ZipCrypto) encryption. Why is this considered weak from a forensic perspective?
- ZipCrypto uses only 40-bit keys that brute force attacks can break instantly
- ZipCrypto is vulnerable to known-plaintext attacks that can recover the key with as little as 12 bytes of known plaintext (Correct answer)
- PKZIP 2.0 stores the password hash in the ZIP header in plaintext
- ZipCrypto archives can be decompressed without a password using standard tools
Correct answer: ZipCrypto is vulnerable to known-plaintext attacks that can recover the key with as little as 12 bytes of known plaintext
The ZipCrypto algorithm is vulnerable to a known-plaintext attack; if an examiner has an unencrypted copy of even one file in the archive, the encryption key can be recovered rapidly.
Question 47: What is a forensic memory dump file used for?
- Creating a verified bit-for-bit copy of a hard disk
- Permanently erasing sensitive files from a drive
- Capturing the contents of RAM at a specific point in time for offline forensic analysis (Correct answer)
- Backing up NTFS MFT records
Correct answer: Capturing the contents of RAM at a specific point in time for offline forensic analysis
A memory dump is a snapshot of RAM contents at the moment of acquisition, enabling offline analysis of volatile artifacts that would otherwise be lost.
Question 48: When imaging a suspect SSD with TRIM support enabled, which concern is most critical for a forensic examiner?
- TRIM can cause the OS to zero-out deleted blocks, permanently destroying recoverable data (Correct answer)
- TRIM renames deleted files to system files
- TRIM may compress data blocks making imaging slower
- TRIM encrypts deleted sectors before wiping
Correct answer: TRIM can cause the OS to zero-out deleted blocks, permanently destroying recoverable data
TRIM instructs the SSD controller to erase blocks associated with deleted files, which can make carved data unrecoverable if the drive is powered on.
Question 49: Which AccessData product is used to manage and coordinate distributed password recovery jobs across multiple machines?
- AD Enterprise with remote agent deployment
- FTK Lab with cluster processing enabled
- PRTK with the DNA (Distributed Network Attack) module (Correct answer)
- Cerberus malware analysis engine
Correct answer: PRTK with the DNA (Distributed Network Attack) module
PRTK's DNA module enables examiners to distribute password cracking jobs across many networked machines, pooling computing resources for faster recovery.
Question 50: What is the primary goal of digital forensics?
- Prevent all cyber threats
- Preserve and analyze digital evidence (Correct answer)
- Modify evidence to match legal needs
- Erase data from storage devices
Correct answer: Preserve and analyze digital evidence
The primary goal of digital forensics is to systematically identify, preserve, collect, analyze, and present digital evidence in a manner that maintains its integrity and admissibility in legal proceedings. This process aims to uncover facts related to a digital incident or crime without altering the original data. It ensures that findings are reliable and can withstand scrutiny.
Question 51: What forensic information does a Windows LNK (shortcut) file provide?
- All installed applications and their install dates
- The current user's NTLM password hash
- A list of active network connections at creation time
- Details about the target file including original path, volume serial number, and timestamps (Correct answer)
Correct answer: Details about the target file including original path, volume serial number, and timestamps
LNK files record metadata about the target file including its original path, host volume information, and MAC timestamps, revealing user file access history.
Question 52: Which file system metadata attribute records the last time a file's content was modified on NTFS?
- Last Accessed time
- Entry Modified time ($STANDARD_INFORMATION)
- Last Written time ($STANDARD_INFORMATION) (Correct answer)
- $MFT entry creation time
Correct answer: Last Written time ($STANDARD_INFORMATION)
The Last Written timestamp in $STANDARD_INFORMATION records when the file's data content was last changed.
Question 53: In FTK, when a file is flagged as 'encrypted' after processing, what does this determination typically rely on?
- The file being located in a system-protected directory
- File header signatures, entropy analysis, and known encryption format identification (Correct answer)
- The file extension matching a known encrypted format list
- The file owner's account being marked as restricted
Correct answer: File header signatures, entropy analysis, and known encryption format identification
FTK combines file signature recognition, known encryption format headers, and high-entropy measurements to identify encrypted files, rather than relying solely on extensions.
Question 54: Which action violates proper chain of custody during evidence handling?
- Allowing an untrained officer to handle the drive without documentation (Correct answer)
- Sealing evidence in a tamper-evident bag
- Photographing the evidence before collection
- Logging each person who accesses the evidence bag
Correct answer: Allowing an untrained officer to handle the drive without documentation
Allowing undocumented access by an untrained person creates a gap in chain of custody and may render the evidence inadmissible.
Question 55: An examiner finds a VeraCrypt-encrypted container on a suspect's drive. What is the most practical forensic approach when no password is known?
- Use FTK's built-in VeraCrypt decryption module
- Declare the evidence unrecoverable and document the encrypted container
- Search the system for passwords in plaintext artifacts (browser saved passwords, text files, registry) before attempting cracking (Correct answer)
- Immediately image the container and submit it for brute force cracking
Correct answer: Search the system for passwords in plaintext artifacts (browser saved passwords, text files, registry) before attempting cracking
Before resource-intensive cracking, examiners should search the broader system for password hints or reuse in artifacts like browser stores, documents, or registry keys, which often succeeds faster.
Question 56: What is the function of a write blocker in forensic investigations?
- Speed up the copying of files
- Compress evidence for storage
- Remove duplicate data automatically
- Prevent modifications to digital evidence (Correct answer)
Correct answer: Prevent modifications to digital evidence
The primary function of a write blocker in forensic investigations is to physically or logically prevent any data from being written to the original digital evidence source. This ensures that the integrity of the evidence is maintained during the acquisition and examination process, preventing accidental or intentional alteration. Write blockers are crucial for adhering to the principle of non-alteration of evidence.
Question 57: What does 'chain of custody' mean in digital forensic investigations?
- A software dependency chain used by forensic tools
- The sequence of network hops traced during a cyber investigation
- The documented, unbroken chronological record of who handled evidence, when, and under what conditions (Correct answer)
- A linked list of file system clusters allocated to a file
Correct answer: The documented, unbroken chronological record of who handled evidence, when, and under what conditions
Chain of custody documents every person who handled the evidence and all transfers, maintaining its integrity and ensuring its admissibility in legal proceedings.
Question 58: When documenting volatile data collection, which piece of information is most critical to capture first?
- The system date and time (Correct answer)
- The IP address of the forensic workstation
- The suspect's name
- The color of the computer case
Correct answer: The system date and time
Recording the system date and time at the start of volatile data collection establishes a temporal reference for all subsequent documentation.
Question 59: What critical data does RAM (volatile memory) analysis reveal that traditional disk forensics cannot?
- Registry hive files stored on disk
- Files deleted years before the acquisition
- File system allocation maps and MFT records
- Running processes, active network connections, encryption keys, and decrypted data in memory (Correct answer)
Correct answer: Running processes, active network connections, encryption keys, and decrypted data in memory
RAM analysis captures the live system state, including running processes, decrypted content, active connections, and data never written to disk.
Question 60: What is the primary forensic value of Windows Event Logs?
- They store a copy of all files created on the system
- They record every keystroke entered by users
- They contain the full content of deleted files
- They provide a chronological record of system events including logons, service starts, and security actions (Correct answer)
Correct answer: They provide a chronological record of system events including logons, service starts, and security actions
Windows Event Logs (Security, System, Application) record timestamped system events that enable forensic reconstruction of activity timelines.
Question 61: During evidence packaging, which labeling information is LEAST critical to include on the evidence bag?
- Collector's name and badge/employee number
- Description of the item and its collection location
- The retail purchase price of the device (Correct answer)
- Case number and date/time of collection
Correct answer: The retail purchase price of the device
The retail price of a device has no bearing on chain of custody or evidence identification; all other fields are required for proper documentation.
Question 62: In a fitness facility, standardized onboarding procedures for new clients (e.g., PAR-Q, fitness assessments, goal-setting) PRIMARILY serve to:
- Ensure consistent, safe, and effective service delivery across all clients (Correct answer)
- Reduce the time required per session for experienced trainers
- Limit the trainer's liability in case of client injury lawsuits
- Fulfill ACE continuing education requirements automatically
Correct answer: Ensure consistent, safe, and effective service delivery across all clients
Standardized onboarding procedures are quality assurance systems that promote consistency, safety, and effectiveness across all client interactions.
Question 63: What is 'slack space' in digital forensics?
- Space reserved for the MFT expansion zone
- The unused area between the logical end of a file and the physical end of its last allocated cluster (Correct answer)
- Unpartitioned space at the end of a disk
- Free space available for new file creation
Correct answer: The unused area between the logical end of a file and the physical end of its last allocated cluster
Slack space is the residual area from where a file's data ends to the physical boundary of the last allocated storage cluster, which can contain remnants of previous data.
Question 64: Which FTK Imager feature is used to acquire a live memory dump from a running Windows system?
- Mount Image to Drive Letter
- Add Evidence Item
- Capture Memory (Correct answer)
- Create Disk Image
Correct answer: Capture Memory
FTK Imager's 'Capture Memory' option acquires the contents of RAM from a running system and writes it to a .mem or .dmp file for offline analysis.
Question 65: The Computer Fraud and Abuse Act (CFAA) 18 U.S.C. ยง 1030 prohibits unauthorized access to protected computers. Which element is most critical to establishing a CFAA violation?
- The defendant must have caused more than $500 in damages
- Access must have been 'without authorization' or 'exceeding authorized access' (Correct answer)
- The crime must cross state lines to be federal
- The defendant must have used encryption to conceal the intrusion
Correct answer: Access must have been 'without authorization' or 'exceeding authorized access'
The core element of a CFAA violation is accessing a protected computer 'without authorization' or by 'exceeding authorized access,' making this the threshold issue in any CFAA case.
Question 66: What is the purpose of using a Faraday bag during mobile device acquisition?
- Prevent electrostatic discharge from damaging the device
- Compress file system data for storage
- Block wireless signals to prevent remote wipe commands (Correct answer)
- Keep the device charged during transport
Correct answer: Block wireless signals to prevent remote wipe commands
A Faraday bag blocks cellular, Wi-Fi, and Bluetooth signals, preventing remote wipe or data modification commands from reaching the device.
Question 67: In a dictionary attack, what is the primary source material used to attempt password recovery?
- Previously known plaintext-ciphertext pairs
- Precomputed hash values stored in tables
- A predefined list of common words and phrases (Correct answer)
- All possible character combinations up to a set length
Correct answer: A predefined list of common words and phrases
A dictionary attack uses a wordlist of common passwords, words, or phrases as candidates, making it effective against weak or common passwords.
Question 68: In FTK's email analysis, which artifact from a Microsoft Outlook PST file is most valuable for establishing a timeline of suspect communications?
- Individual email sent and received timestamps stored in the message properties (Correct answer)
- The Outlook profile registry key last write time
- The PST file's last modified timestamp on disk
- The OST synchronization log
Correct answer: Individual email sent and received timestamps stored in the message properties
Individual message properties within a PST store precise sent and received timestamps that are more reliable for timeline reconstruction than file system metadata.
Question 69: Which cloud acquisition scenario presents the greatest legal complexity for a forensic examiner?
- Acquiring data from a locally-synced cloud folder on a seized laptop
- Extracting cached cloud files from browser history
- Obtaining data directly from a cloud provider's servers across international jurisdictions (Correct answer)
- Imaging a locally-attached USB drive containing cloud backup files
Correct answer: Obtaining data directly from a cloud provider's servers across international jurisdictions
Cross-border cloud data requests require compliance with international laws (e.g., GDPR, MLAT treaties), making them legally complex beyond domestic warrant authority.
Question 70: Which concept describes using a known hash value to quickly verify a file's identity without examining its content?
- Entropy analysis
- Hash matching or hash verification (Correct answer)
- Metadata analysis
- File carving
Correct answer: Hash matching or hash verification
Hash matching compares a computed hash (MD5, SHA-1, SHA-256) against a known reference value to confirm identity or detect modification without reading the file content.
Question 71: What is AccessData's DNA (Distributed Network Attack) feature primarily used for?
- Distributing password cracking workloads across networked computers (Correct answer)
- Managing distributed forensic case files
- Decrypting SSL/TLS communications
- Analyzing network traffic captures
Correct answer: Distributing password cracking workloads across networked computers
DNA leverages multiple networked machines to parallelize and accelerate password recovery operations, dramatically reducing cracking time.
Question 72: What distinguishes a logical acquisition from a physical acquisition of a mobile device?
- Logical acquisition captures deleted data; physical does not
- Physical acquisition works only on iOS devices
- Logical acquisition requires a write-blocker; physical does not
- Physical acquisition captures the complete bit-stream; logical captures only accessible files (Correct answer)
Correct answer: Physical acquisition captures the complete bit-stream; logical captures only accessible files
Physical acquisition captures the entire raw storage including deleted and unallocated space, while logical acquisition retrieves only the active file system.
Question 73: What does 'verification' mean in the context of a forensic image created with FTK Imager?
- Confirming the suspect's identity before imaging
- Checking that the image file extension is correct
- Validating that the image is password-protected
- Re-hashing the completed image and comparing it to the hash computed during acquisition (Correct answer)
Correct answer: Re-hashing the completed image and comparing it to the hash computed during acquisition
Verification re-computes the hash of the finished image and compares it to the acquisition-time hash to confirm the image is an exact, unaltered copy.
Question 74: What does the Windows 'UserAssist' registry key track, and how is its data encoded?
- GUI-based program execution history with run counts and timestamps, encoded in ROT13 (Correct answer)
- Recently printed documents, encoded in hexadecimal
- Recently connected USB devices, encoded in Base64
- Active network adapter settings, stored in plain text
Correct answer: GUI-based program execution history with run counts and timestamps, encoded in ROT13
UserAssist entries, stored ROT13-encoded under HKCU, record the history of programs launched through Windows Explorer including execution counts and last-run timestamps.
Question 75: What is the difference between a 'forensic duplicate' and a 'forensic image'?
- A forensic image is a bit-for-bit copy stored in a container format (e.g., E01); a forensic duplicate is a physical sector-by-sector clone to another drive (Correct answer)
- There is no difference; the terms are always interchangeable
- A forensic duplicate is a hash-verified bit-for-bit copy; a forensic image is a compressed archive of active files only
- A forensic duplicate excludes slack space; a forensic image includes it
Correct answer: A forensic image is a bit-for-bit copy stored in a container format (e.g., E01); a forensic duplicate is a physical sector-by-sector clone to another drive
A forensic image stores the bit-for-bit copy in a container file (like E01 or DD), while a forensic duplicate is a physical sector-by-sector clone onto another physical drive.
Question 76: What is 'sparse acquisition' in the context of mobile device forensics?
- Acquiring data over a slow Bluetooth connection
- Imaging only non-empty, allocated regions of storage to reduce image size (Correct answer)
- Extracting only deleted files using carving
- Acquiring only the SIM card data
Correct answer: Imaging only non-empty, allocated regions of storage to reduce image size
Sparse acquisition skips empty (zeroed) sectors and records only blocks with actual data, significantly reducing image size for large-capacity devices.
Question 77: What forensic value does the Windows hiberfil.sys file provide?
- It stores a backup of the Windows registry hives
- It contains a compressed snapshot of RAM from the last system hibernation event (Correct answer)
- It holds browser session cookies from the last active user session
- It logs all application crashes and error codes
Correct answer: It contains a compressed snapshot of RAM from the last system hibernation event
Hiberfil.sys stores a compressed image of RAM contents saved during hibernation, serving as a partial memory dump available for offline forensic analysis.
Question 78: What is the foundation of professional ethics in this field?
- Prioritizing organizational politics
- Acting in the best interest of stakeholders while maintaining integrity (Correct answer)
- Maximizing personal financial gain
- Following only the minimum legal requirements
Correct answer: Acting in the best interest of stakeholders while maintaining integrity
Professional ethics is fundamentally about acting with integrity and in the best interest of all stakeholders, going beyond mere legal compliance.
Question 79: What does "system integration" mean in a technology context?
- Connecting different technology systems to work together and share data seamlessly (Correct answer)
- Using the same password for all systems
- Replacing all existing systems with a single new system
- Installing systems in the same physical location
Correct answer: Connecting different technology systems to work together and share data seamlessly
System integration involves connecting different technology systems, applications, or platforms so they can work together, share data, and provide a cohesive user experience.
Question 80: A forensic examiner needs to analyze SQLite databases found on a mobile device backup. Which FTK capability supports this?
- The file carving engine
- FTK's built-in SQLite viewer and data extraction tools (Correct answer)
- The email threading module
- The KFF library comparison
Correct answer: FTK's built-in SQLite viewer and data extraction tools
FTK includes a SQLite viewer that can parse and display database contents from mobile app databases such as SMS, contacts, and browser history stores.
Question 81: What does the acronym 'MFT' stand for in NTFS forensics?
- Master Format Table
- Master File Table (Correct answer)
- Main File Tracker
- Metadata Function Table
Correct answer: Master File Table
The Master File Table (MFT) is the core NTFS structure that stores metadata records for every file and directory on the volume.
Question 82: In FTK, what is the purpose of the 'Detailed Options' hash verification step during evidence processing?
- To compute and record cryptographic hash values (MD5/SHA-1) of evidence items to verify integrity throughout the investigation (Correct answer)
- To index only image files while skipping documents
- To automatically redact sensitive data from the evidence set
- To compress evidence files before storage
Correct answer: To compute and record cryptographic hash values (MD5/SHA-1) of evidence items to verify integrity throughout the investigation
FTK computes MD5 and SHA-1 hashes during evidence processing to create a verifiable integrity baseline, confirming that evidence has not been altered.
Question 83: What is 'prefetch' analysis used for in a Windows forensic investigation?
- Identifying encrypted volumes on a drive
- Recovering deleted emails from PST files
- Determining which applications were executed and when on a Windows system (Correct answer)
- Mapping network shares accessed by the suspect
Correct answer: Determining which applications were executed and when on a Windows system
Windows Prefetch files (.pf) record application execution data including run count and last run time, proving program execution even after the executable is deleted.
Question 84: Why is timestamping an evidence collection log with UTC rather than local time considered best practice?
- UTC eliminates ambiguity from daylight saving time changes and time zone differences across jurisdictions (Correct answer)
- Courts do not accept local time zone evidence
- UTC is faster to type than local time zone abbreviations
- FTK only stores timestamps in UTC format
Correct answer: UTC eliminates ambiguity from daylight saving time changes and time zone differences across jurisdictions
UTC is a universal reference that avoids the confusion of daylight saving adjustments and cross-jurisdiction time zone discrepancies in multi-location investigations.
Question 85: When recovering passwords for Microsoft Office documents (.docx, .xlsx) protected with AES-256 encryption (Office 2016+), what approach is most realistic for an examiner?
- Directly decrypting the file using FTK's Office decryption engine
- Extracting the password from the document's XML metadata
- Dictionary or rule-based attacks combined with GPU acceleration, since AES-256 itself is not feasibly broken (Correct answer)
- Using a known-plaintext attack against the Office encryption format
Correct answer: Dictionary or rule-based attacks combined with GPU acceleration, since AES-256 itself is not feasibly broken
Modern Office encryption using AES-256 is cryptographically strong; examiners rely on password-guessing attacks (dictionary, rules, GPU-assisted) rather than breaking the encryption algorithm itself.
Question 86: What is a 'sector' in the context of hard drive forensics?
- A cluster of allocated files
- A logical grouping of related files
- The smallest addressable unit of storage on a physical disk, traditionally 512 bytes (Correct answer)
- A partition on a hard drive
Correct answer: The smallest addressable unit of storage on a physical disk, traditionally 512 bytes
A sector is the smallest physical storage unit on a hard disk drive, traditionally 512 bytes, though modern drives may use 4096-byte (4K) sectors.
Question 87: A forensic investigator is examining a healthcare organization's systems. Under HIPAA's Security Rule, which category of safeguards requires workforce training and security policies?
- Administrative safeguards (Correct answer)
- Technical safeguards
- Physical safeguards
- Operational safeguards
Correct answer: Administrative safeguards
HIPAA's Administrative Safeguards include workforce security training, security management processes, and written policies โ the organizational rather than technical controls.
Question 88: Which FTK search capability enables examiners to locate structured data patterns like SSNs or credit card numbers across all evidence?
- Known File Filter (KFF) hash matching
- Evidence image mounting
- Regular expression (regex) search (Correct answer)
- Bookmark export and review
Correct answer: Regular expression (regex) search
FTK supports regular expression searches, allowing examiners to define patterns such as \d{3}-\d{2}-\d{4} to locate Social Security numbers or similar structured data across all evidence.
AccessData Certified Examiner (ACE)
The ACE certification validates a digital forensic examiner's proficiency with AccessData's forensic tools including FTK, FTK Imager, Registry Viewer, and Password Recovery Toolkit. It covers evidence acquisition, artifact analysis, network/memory forensics, and legal compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds