← All ACE Flashcard Decks

ACE Network & Memory Forensics Flashcards

6 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 ACE Network & Memory Forensics flashcards as text
  1. What is the primary forensic value of Windows Event Logs?

    Answer: They provide a chronological record of system events including logons, service starts, and security actions

    Windows Event Logs (Security, System, Application) record timestamped system events that enable forensic reconstruction of activity timelines.

  2. Which Windows Security Event ID indicates a successful user account logon?

    Answer: Event ID 4624

    Windows Security Event ID 4624 is logged each time a user account successfully authenticates and establishes a logon session.

  3. Why is the Windows pagefile (pagefile.sys) forensically significant?

    Answer: It holds memory pages swapped from RAM to disk, potentially including process data, fragments of documents, and passwords

    The pagefile contains RAM pages that were swapped to disk, preserving volatile data fragments even after the system is shut down.

  4. What type of traffic does a packet sniffer capture during network forensic analysis?

    Answer: Raw network packets traversing the monitored network interface

    A packet sniffer captures all raw packets at the network interface level, providing complete visibility into communications regardless of protocol.

  5. How does FTK analyze web browsing history from a Windows evidence image?

    Answer: By parsing browser artifact databases such as Chrome and Firefox SQLite files and IE index.dat to extract visited URLs and timestamps

    FTK parses browser-specific artifact files (SQLite databases for Chrome/Firefox, index.dat for IE) to reconstruct browsing history with URLs and timestamps.

  6. What does Windows Security Event ID 4625 indicate?

    Answer: A failed logon attempt occurred

    Event ID 4625 is logged whenever an account fails to authenticate, which is critical for detecting brute force attacks and unauthorized access attempts.