Password Recovery & Decryption Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Password Recovery & Decryption flashcards as text
Which AccessData tool is specifically designed for password recovery and works in conjunction with FTK?
Answer: PRTK (Password Recovery Toolkit)
PRTK (Password Recovery Toolkit) is AccessData's dedicated password recovery tool that integrates with FTK to recover passwords from protected files.
What is AccessData's DNA (Distributed Network Attack) feature primarily used for?
Answer: Distributing password cracking workloads across networked computers
DNA leverages multiple networked machines to parallelize and accelerate password recovery operations, dramatically reducing cracking time.
In a dictionary attack, what is the primary source material used to attempt password recovery?
Answer: A predefined list of common words and phrases
A dictionary attack uses a wordlist of common passwords, words, or phrases as candidates, making it effective against weak or common passwords.
What type of password attack attempts every possible combination of characters up to a specified length?
Answer: Brute force attack
A brute force attack systematically tries all possible character combinations, guaranteeing eventual success but requiring significant time and resources.
What is a rainbow table in the context of password cracking?
Answer: A precomputed table of hash values mapped to their plaintext passwords
Rainbow tables store precomputed hash-to-plaintext mappings, enabling fast password recovery by looking up a hash rather than computing it in real time.
What security mechanism makes rainbow table attacks significantly less effective?
Answer: Salting the password before hashing
Salting adds a unique random value to each password before hashing, ensuring identical passwords produce different hashes and invalidating precomputed rainbow tables.
When FTK identifies an encrypted file during processing, what is the recommended first step before attempting password recovery?
Answer: Check if the password or key material exists elsewhere in the image (e.g., swap file, registry)
Key material, passwords, or encryption artifacts may exist in other areas of the image such as unallocated space, the registry, or hibernation/swap files, providing a faster path than cracking.