Evidence Acquisition & Preservation Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Evidence Acquisition & Preservation flashcards as text
What does 'verification' mean in the context of a forensic image created with FTK Imager?
Answer: Re-hashing the completed image and comparing it to the hash computed during acquisition
Verification re-computes the hash of the finished image and compares it to the acquisition-time hash to confirm the image is an exact, unaltered copy.
An investigator is responding to a ransomware incident. Which evidence should be collected BEFORE isolating the infected system from the network?
Answer: Network connections, active processes, and running memory to identify encryption keys
Active network connections and RAM may contain the ransomware's encryption keys or C2 communication data that disappears upon network isolation or shutdown.
Which file system artifact is MOST useful for proving a USB drive was connected to a Windows system even if the drive has been removed?
Answer: USBSTOR registry keys and Windows Event Log entries on the host
USBSTOR registry entries and Event Log records on the host system log device connection details (serial number, timestamps) independent of the physical USB drive.
What is 'sparse acquisition' in the context of mobile device forensics?
Answer: Imaging only non-empty, allocated regions of storage to reduce image size
Sparse acquisition skips empty (zeroed) sectors and records only blocks with actual data, significantly reducing image size for large-capacity devices.
Why is timestamping an evidence collection log with UTC rather than local time considered best practice?
Answer: UTC eliminates ambiguity from daylight saving time changes and time zone differences across jurisdictions
UTC is a universal reference that avoids the confusion of daylight saving adjustments and cross-jurisdiction time zone discrepancies in multi-location investigations.
During evidence packaging, which labeling information is LEAST critical to include on the evidence bag?
Answer: The retail purchase price of the device
The retail price of a device has no bearing on chain of custody or evidence identification; all other fields are required for proper documentation.
What is the significance of the 'hash set' feature in FTK during evidence processing?
Answer: It compares file hashes against known databases (e.g., NSRL) to quickly identify or exclude known files
Hash sets allow FTK to flag known-good files (e.g., OS files via NSRL) or known-bad files (e.g., CSAM hashes), dramatically narrowing the scope of manual review.