Mixed Deck — All ACE Topics Flashcards
100 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All ACE Topics flashcards as text
What is the appropriate action when discovering a colleague has violated professional standards?
Answer: Report through proper channels as outlined in the code of ethics
Professional standards require reporting violations through proper channels to protect the public and maintain the integrity of the profession.
An examiner is asked by a client to alter timestamps in a forensic report to make evidence appear collected earlier. The examiner should:
Answer: Refuse; altering report data constitutes evidence tampering and obstruction of justice
Altering forensic report data is evidence tampering and obstruction of justice, violating both criminal law and professional ethics.
Which conflict resolution approach is most effective in ACORD Certified Expert practice?
Answer: Collaborative problem-solving with all parties
Collaborative problem-solving involves all parties working together to find a mutually beneficial solution.
An examiner uses FTK to examine a TrueCrypt/VeraCrypt volume. Which analysis approach is MOST appropriate when the passphrase is unknown?
Answer: Attempt password recovery with PRTK/DNA against the volume header, or seek a keyfile/passphrase from other evidence
Without a known passphrase, the examiner should use PRTK/DNA for password recovery against the volume header or search other evidence sources for the passphrase or keyfile.
What is the purpose of FTK's Known File Filter (KFF)?
Answer: Identify files by known hash values to flag or exclude them, reducing manual review workload
FTK's KFF uses hash libraries such as NSRL to automatically identify known-good or known-bad files, letting examiners focus on unknown or suspicious items.
Which legal concept requires that the methods used by a forensic expert be generally accepted within the relevant scientific community?
Answer: Frye Standard
The Frye standard, used in some U.S. states, requires expert methodology to be generally accepted in the relevant scientific community.
In FTK's timeline analysis feature, what primary benefit does correlating file system events with registry and log timestamps provide?
Answer: It reconstructs a chronological sequence of user and system activity to establish a narrative of events
Correlating multiple timestamp sources across file system, registry, and event logs creates a comprehensive activity timeline that shows what happened, in what order, and when.
What is AccessData's DNA (Distributed Network Attack) feature primarily used for?
Answer: Distributing password cracking workloads across networked computers
DNA leverages multiple networked machines to parallelize and accelerate password recovery operations, dramatically reducing cracking time.
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to implement a comprehensive information security program primarily to protect what type of information?
Answer: Nonpublic personal information (NPI) of customers
GLBA's Safeguards Rule mandates that financial institutions protect nonpublic personal information (NPI) of their customers through a written, comprehensive security program.
Which AccessData utility is designed to triage and acquire evidence from mobile devices in the field?
Answer: MPE+ (Mobile Phone Examiner Plus)
MPE+ is AccessData's dedicated mobile forensics tool for acquiring and analyzing data from smartphones and tablets.
In a corporate investigation, an examiner is asked to collect evidence from an employee's cloud storage account. What is the most critical first step?
Answer: Obtain proper legal authority such as a warrant, consent, or court order before accessing the account
Accessing cloud accounts without proper legal authority may violate the Stored Communications Act and other laws, rendering the evidence inadmissible.
In FTK, what is the purpose of the 'Detailed Options' hash verification step during evidence processing?
Answer: To compute and record cryptographic hash values (MD5/SHA-1) of evidence items to verify integrity throughout the investigation
FTK computes MD5 and SHA-1 hashes during evidence processing to create a verifiable integrity baseline, confirming that evidence has not been altered.
An examiner's workstation is compromised by malware mid-investigation. Which risk was insufficiently mitigated?
Answer: Examiner workstation integrity risk
Malware on the examiner's workstation represents a failure to mitigate workstation integrity risk, which can contaminate forensic analysis results.
Which concept describes using a known hash value to quickly verify a file's identity without examining its content?
Answer: Hash matching or hash verification
Hash matching compares a computed hash (MD5, SHA-1, SHA-256) against a known reference value to confirm identity or detect modification without reading the file content.
An ACE examiner finds a file with a creation timestamp that is LATER than its last modified timestamp. What is the MOST likely explanation?
Answer: The file was copied to this location after it was originally created and modified elsewhere
When a file is copied to a new location, Windows updates the creation timestamp to the copy time, which can make it later than the original modification timestamp from the source.
In a U.S. federal investigation, what legal authority does a forensic examiner need to search and seize digital evidence from a third-party cloud provider?
Answer: A search warrant or court order under 18 U.S.C. § 2703
Under the Stored Communications Act (18 U.S.C. § 2703), law enforcement must obtain a warrant, court order, or subpoena depending on the type and age of stored data.
What is a root cause analysis used for?
Answer: To identify the underlying cause of a problem rather than just addressing symptoms
Root cause analysis is a systematic method used to identify the fundamental underlying cause of a problem, enabling solutions that prevent recurrence rather than just treating symptoms.
During an ACE examination, an examiner identifies that a suspect's cloud storage account contains potential evidence. What risk must be mitigated before legal acquisition?
Answer: Risk of evidence destruction due to account termination or file deletion
Cloud evidence can be deleted or accounts terminated; legal preservation orders (holds) should be sought immediately to mitigate this evidence destruction risk.
When examining a BitLocker-encrypted drive, which of the following is the most examiner-friendly recovery method if the recovery key is unavailable?
Answer: Searching the Microsoft account or Active Directory for the stored BitLocker Recovery Key
BitLocker recovery keys are automatically backed up to Microsoft accounts or Active Directory, making this the fastest and most reliable recovery path for examiners.
A forensic examiner is analyzing Windows artifacts and wants to determine what USB devices were previously connected to a system. Which registry hive should they examine?
Answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR registry key records details about USB storage devices that have been connected to the system, including device identifiers.