← All ACE Flashcard Decks

Advanced Techniques & Methods Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Advanced Techniques & Methods flashcards as text
  1. When FTK processes email evidence in PST or OST format, which artifact provides the strongest proof of message transmission rather than mere composition?

    Answer: Sent Items folder with matching server message ID headers

    Messages in the Sent Items folder with matching SMTP headers (Message-ID, Received fields) confirm actual transmission through a mail server, not just local drafting.

  2. In the context of AccessData FTK, what does the 'Cerberus' malware analysis module provide?

    Answer: Automated behavioral and static analysis of suspect executables to detect malware characteristics

    Cerberus performs automated malware triage on executable files using static analysis (PE structure, imports, strings) and behavioral indicators without requiring detonation.

  3. A suspect used steganography to hide data within image files. Which FTK-integrated approach helps detect this?

    Answer: Using steganalysis tools and comparing file sizes to expected sizes for image dimensions

    Steganalysis involves statistical analysis and comparing actual file sizes to expected sizes, since steganographic embedding often increases file size beyond what image data alone would require.

  4. What is the forensic significance of Windows Volume Shadow Copies (VSCs) when analyzing a compromised system?

    Answer: VSCs preserve point-in-time snapshots of files allowing recovery of earlier file versions and deleted data

    Volume Shadow Copies are point-in-time snapshots of a volume's state, allowing examiners to recover previous versions of files, examine deleted files, and identify changes over time.

  5. During a network intrusion investigation, an examiner finds $MFT records with a $STANDARD_INFORMATION timestamp earlier than the $FILE_NAME timestamp. What does this most likely indicate?

    Answer: Timestomping — deliberate manipulation of $STANDARD_INFORMATION timestamps to obscure file activity

    Timestomping tools modify $STANDARD_INFORMATION timestamps (visible in Windows Explorer) but often fail to alter $FILE_NAME timestamps, creating a detectable inconsistency.

  6. When conducting a forensic examination of a BitLocker-encrypted drive, what is the first information the examiner must obtain before decryption is possible in FTK?

    Answer: The BitLocker recovery key or user password

    BitLocker requires the recovery key (48-digit numerical key stored in AD, Microsoft account, or USB) or the user's password to decrypt the volume before examination can proceed.

  7. In FTK's timeline analysis feature, what primary benefit does correlating file system events with registry and log timestamps provide?

    Answer: It reconstructs a chronological sequence of user and system activity to establish a narrative of events

    Correlating multiple timestamp sources across file system, registry, and event logs creates a comprehensive activity timeline that shows what happened, in what order, and when.