โ† All ACE Flashcard Decks

Foundational Concepts & Principles Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Foundational Concepts & Principles flashcards as text
  1. What is the significance of the MD5 hash value in digital forensics?

    Answer: It provides a unique fingerprint to verify a file or image has not been altered

    MD5 produces a fixed-length digest that acts as a fingerprint; any change to the data produces a different hash, verifying integrity.

  2. What is 'unallocated space' on a hard drive?

    Answer: Clusters not currently assigned to any file by the file system

    Unallocated space consists of clusters that are not assigned to active files and may contain remnants of deleted files.

  3. In the context of the ACE exam, what does 'email header analysis' primarily help an investigator determine?

    Answer: The routing path and originating IP address of an email

    Email headers contain Received fields that trace the servers the message passed through, helping identify the origin IP and routing path.

  4. Which standard governs the admissibility of scientific evidence in US federal courts based on peer review and general acceptance?

    Answer: Daubert Standard

    The Daubert Standard, established in Daubert v. Merrell Dow Pharmaceuticals (1993), requires federal courts to evaluate scientific testimony for reliability and relevance.

  5. What is the purpose of a 'forensic image' as opposed to a simple file copy?

    Answer: A forensic image captures every bit of the source drive including unallocated and slack space

    A forensic image (bit-for-bit copy) captures the entire drive including deleted data, slack space, and unallocated areas that a file copy would miss.

  6. What Windows Registry hive stores user-specific settings and is loaded from the NTUSER.DAT file?

    Answer: HKEY_CURRENT_USER

    HKEY_CURRENT_USER is loaded from the currently logged-in user's NTUSER.DAT profile file and stores that user's personal settings.

  7. What is the 'order of volatility' principle used for in digital forensics?

    Answer: Prioritizing collection of evidence that will disappear fastest first

    The order of volatility guides investigators to collect the most transient data (RAM, network state) before less volatile data (hard drive contents).