โ† All ACE Flashcard Decks

ACE File System & Artifact Analysis Flashcards

6 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 ACE File System & Artifact Analysis flashcards as text
  1. What forensic information does the Windows 'Jump List' artifact provide?

    Answer: Recently and frequently accessed files associated with specific applications

    Jump Lists store per-application records of recently and frequently accessed files, tied to unique Application IDs, revealing targeted user activity.

  2. What does FTK's Graphics Viewer (thumbnail gallery) allow an examiner to do?

    Answer: Visually browse all images found across the entire evidence set in a thumbnail layout

    FTK's Graphics Viewer displays thumbnails of all images found in the evidence set, enabling rapid visual scanning without opening each file individually.

  3. Which Windows registry hive stores settings and preferences specific to the currently logged-on user?

    Answer: HKEY_CURRENT_USER (HKCU)

    HKCU contains configuration data specific to the currently logged-on user, loaded from that user's NTUSER.DAT file at login.

  4. What does FTK's 'live search' capability allow an examiner to do?

    Answer: Search for keywords or patterns across evidence data without waiting for full indexing

    FTK's live search lets examiners run keyword or regex searches directly against evidence data immediately without requiring a completed index.

  5. What does the Windows 'ShellBags' artifact record?

    Answer: Folder browsing history including view settings for folders that may have since been deleted

    ShellBags store Windows Explorer folder view settings and access history in the registry, persisting even after the accessed folders are deleted.

  6. In FTK, what does mounting a forensic image as a drive letter allow an examiner to do?

    Answer: Access the image through Windows Explorer or third-party tools as if it were a live disk, in read-only mode

    Mounting a forensic image assigns it a drive letter for read-only access, enabling third-party tools to interact with the evidence without altering it.