โ† All ACE Flashcard Decks

ACE Network & Memory Forensics Flashcards

6 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 ACE Network & Memory Forensics flashcards as text
  1. What critical data does RAM (volatile memory) analysis reveal that traditional disk forensics cannot?

    Answer: Running processes, active network connections, encryption keys, and decrypted data in memory

    RAM analysis captures the live system state, including running processes, decrypted content, active connections, and data never written to disk.

  2. According to the order of volatility, which data source must be collected FIRST at a live scene?

    Answer: RAM/memory contents

    RAM is the most volatile data source and must be captured before any other action, as it is destroyed immediately when the system loses power.

  3. Which FTK Imager feature is used to acquire a live memory dump from a running Windows system?

    Answer: Capture Memory

    FTK Imager's 'Capture Memory' option acquires the contents of RAM from a running system and writes it to a .mem or .dmp file for offline analysis.

  4. What is a forensic memory dump file used for?

    Answer: Capturing the contents of RAM at a specific point in time for offline forensic analysis

    A memory dump is a snapshot of RAM contents at the moment of acquisition, enabling offline analysis of volatile artifacts that would otherwise be lost.

  5. Which Windows registry location stores previously connected wireless (Wi-Fi) network profiles?

    Answer: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles and WLAN event logs

    Windows stores Wi-Fi network history in the NetworkList registry key and WLAN AutoConfig event logs, which can reveal location history based on network associations.

  6. What does analyzing DNS artifacts during network forensics help an investigator determine?

    Answer: Which domain names a system resolved, revealing connections to websites, C2 servers, or exfiltration targets

    DNS resolution records show which domain names a host looked up, helping establish communications with malicious domains, C2 infrastructure, or unauthorized services.