Foundational Concepts & Principles Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Foundational Concepts & Principles flashcards as text
What Windows artifact, stored in the SYSTEM registry hive, records USB devices that have been connected to a computer?
Answer: USBSTOR key
The USBSTOR registry key in HKLM\SYSTEM records detailed information about every USB storage device that has been connected to the system.
What is 'hash set analysis' used for in FTK?
Answer: Automatically categorizing files as known good, known bad, or unknown by comparing hashes against a database
Hash set analysis compares file hashes against reference databases (like NSRL) to quickly identify known operating system files or known malicious files.
What does 'timestomping' refer to in a forensic investigation?
Answer: Deliberately manipulating file timestamps to mislead investigators or establish a false alibi
Timestomping is an anti-forensic technique where an attacker or suspect alters file timestamps to obscure when files were created, modified, or accessed.
In digital forensics, what does 'steganography' refer to?
Answer: Hiding data within another file (such as an image or audio file) to conceal its existence
Steganography conceals the existence of data by embedding it within an innocuous carrier file, unlike encryption which only conceals content.
What is the purpose of the 'Prefetch' files found in C:\Windows\Prefetch on Windows systems?
Answer: They record application execution history including the executable name and run count to speed up future launches
Prefetch files help Windows load applications faster by pre-caching data, and forensically they record execution history including timestamps and run counts.
Which FTK feature allows an investigator to search for specific text strings across all evidence files simultaneously?
Answer: Index Search (Live Search / dtSearch)
FTK's dtSearch index allows investigators to perform fast keyword searches across all indexed evidence files and carve results simultaneously.
What is a 'sector' in the context of hard drive forensics?
Answer: The smallest addressable unit of storage on a physical disk, traditionally 512 bytes
A sector is the smallest physical storage unit on a hard disk drive, traditionally 512 bytes, though modern drives may use 4096-byte (4K) sectors.