← All ACE Flashcard Decks

Password Recovery & Decryption Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Password Recovery & Decryption flashcards as text
  1. What is a rule-based (or hybrid) attack in PRTK?

    Answer: Applying transformation rules (e.g., capitalize, append numbers) to dictionary words to generate candidates

    A rule-based attack applies mutations — such as capitalization, substitution, or appending digits — to dictionary entries to cover predictable password patterns.

  2. Windows EFS (Encrypting File System) stores decryption key material in which location?

    Answer: The user's certificate store tied to their Windows account credentials

    EFS uses the user's private key stored in their certificate store; if the examiner can log in as the user or export the certificate, EFS-protected files can be decrypted.

  3. When examining a BitLocker-encrypted drive, which of the following is the most examiner-friendly recovery method if the recovery key is unavailable?

    Answer: Searching the Microsoft account or Active Directory for the stored BitLocker Recovery Key

    BitLocker recovery keys are automatically backed up to Microsoft accounts or Active Directory, making this the fastest and most reliable recovery path for examiners.

  4. GPU acceleration in password cracking provides a significant advantage primarily because GPUs:

    Answer: Contain thousands of cores optimized for parallel mathematical operations

    GPUs contain thousands of small cores designed for parallel processing, allowing them to compute millions of hash comparisons simultaneously — far exceeding CPU performance for cracking tasks.

  5. What does FTK's 'Known File Filter' (KFF) contribute to a password recovery workflow?

    Answer: It excludes known benign files from processing, allowing the examiner to focus on unknown or suspect encrypted files

    KFF filters out known-good files (e.g., OS and application files), reducing the dataset so examiners concentrate password recovery efforts on genuinely unknown, potentially relevant encrypted files.

  6. A suspect's password-protected ZIP archive uses PKZIP 2.0 (ZipCrypto) encryption. Why is this considered weak from a forensic perspective?

    Answer: ZipCrypto is vulnerable to known-plaintext attacks that can recover the key with as little as 12 bytes of known plaintext

    The ZipCrypto algorithm is vulnerable to a known-plaintext attack; if an examiner has an unencrypted copy of even one file in the archive, the encryption key can be recovered rapidly.

  7. In FTK, when a file is flagged as 'encrypted' after processing, what does this determination typically rely on?

    Answer: File header signatures, entropy analysis, and known encryption format identification

    FTK combines file signature recognition, known encryption format headers, and high-entropy measurements to identify encrypted files, rather than relying solely on extensions.