โ† All ACE Flashcard Decks

Advanced Techniques & Methods Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Advanced Techniques & Methods flashcards as text
  1. When examining a password-protected ZIP archive in FTK, which technique is most appropriate for recovery without a known password?

    Answer: Apply dictionary attack using a custom wordlist

    A dictionary attack using a custom wordlist tailored to the suspect's known terms is the most targeted and legally defensible approach for ZIP password recovery in FTK.

  2. In FTK, what is the purpose of the 'Known File Filter' (KFF) during evidence processing?

    Answer: Flags or ignores files based on hash comparison to known good/bad libraries

    KFF compares file hashes against databases of known good (OS/application) and known bad (malware/contraband) files to quickly triage evidence.

  3. An investigator finds a file with a .jpg extension but FTK flags it as a mismatch. What does this most likely indicate?

    Answer: The file extension was changed to disguise its true file type

    A header/extension mismatch typically indicates intentional obfuscation where a file's extension was manually changed to hide its true content type.

  4. Which of the following best describes 'live acquisition' in digital forensics?

    Answer: Collecting volatile data from a running system before shutdown

    Live acquisition involves capturing volatile data (RAM, network connections, running processes) from a powered-on system, which would be lost upon shutdown.

  5. When using FTK's bookmarking feature during an investigation, what is the primary forensic purpose?

    Answer: To organize and annotate evidentiary items for reporting and court presentation

    Bookmarks allow examiners to flag, categorize, and annotate specific files or artifacts for inclusion in reports and to clearly communicate findings in court.

  6. A forensic examiner discovers 'unallocated space' containing file fragments. Which FTK feature best helps recover these fragments?

    Answer: File carving using header/footer signatures

    File carving scans raw binary data for known file headers and footers to reconstruct files from unallocated space without relying on file system metadata.

  7. During NTFS forensics in FTK, what critical information is stored in the Master File Table (MFT) that aids an investigation?

    Answer: File metadata including timestamps, permissions, file names, and attribute data

    The MFT contains comprehensive metadata for every file and directory, including MAC timestamps, file size, permissions, and data run locations on disk.