ACE Network & Memory Forensics Flashcards
6 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 ACE Network & Memory Forensics flashcards as text
What is 'anti-forensics' in the context of digital investigations?
Answer: Techniques used to destroy, conceal, or manipulate digital evidence to impede forensic investigations
Anti-forensics encompasses methods such as file wiping, timestamp alteration, steganography, and encryption used to obstruct or invalidate forensic analysis.
What forensic value does the Windows hiberfil.sys file provide?
Answer: It contains a compressed snapshot of RAM from the last system hibernation event
Hiberfil.sys stores a compressed image of RAM contents saved during hibernation, serving as a partial memory dump available for offline forensic analysis.
Which FTK search capability enables examiners to locate structured data patterns like SSNs or credit card numbers across all evidence?
Answer: Regular expression (regex) search
FTK supports regular expression searches, allowing examiners to define patterns such as \d{3}-\d{2}-\d{4} to locate Social Security numbers or similar structured data across all evidence.
What does the Windows 'UserAssist' registry key track, and how is its data encoded?
Answer: GUI-based program execution history with run counts and timestamps, encoded in ROT13
UserAssist entries, stored ROT13-encoded under HKCU, record the history of programs launched through Windows Explorer including execution counts and last-run timestamps.
What does 'chain of custody' mean in digital forensic investigations?
Answer: The documented, unbroken chronological record of who handled evidence, when, and under what conditions
Chain of custody documents every person who handled the evidence and all transfers, maintaining its integrity and ensuring its admissibility in legal proceedings.
In FTK, what is the purpose of the 'Detailed Options' hash verification step during evidence processing?
Answer: To compute and record cryptographic hash values (MD5/SHA-1) of evidence items to verify integrity throughout the investigation
FTK computes MD5 and SHA-1 hashes during evidence processing to create a verifiable integrity baseline, confirming that evidence has not been altered.