← All ACE Flashcard Decks

Password Recovery & Decryption Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Password Recovery & Decryption flashcards as text
  1. Which AccessData product is used to manage and coordinate distributed password recovery jobs across multiple machines?

    Answer: PRTK with the DNA (Distributed Network Attack) module

    PRTK's DNA module enables examiners to distribute password cracking jobs across many networked machines, pooling computing resources for faster recovery.

  2. An examiner finds a VeraCrypt-encrypted container on a suspect's drive. What is the most practical forensic approach when no password is known?

    Answer: Search the system for passwords in plaintext artifacts (browser saved passwords, text files, registry) before attempting cracking

    Before resource-intensive cracking, examiners should search the broader system for password hints or reuse in artifacts like browser stores, documents, or registry keys, which often succeeds faster.

  3. What is key escrow, and how is it relevant to digital forensic investigations?

    Answer: A system where encryption keys are held by a trusted third party, potentially allowing lawful access without breaking encryption

    Key escrow allows authorized parties (such as law enforcement with proper legal process) to obtain encryption keys from the holding third party, enabling decryption without cryptanalysis.

  4. When recovering passwords for Microsoft Office documents (.docx, .xlsx) protected with AES-256 encryption (Office 2016+), what approach is most realistic for an examiner?

    Answer: Dictionary or rule-based attacks combined with GPU acceleration, since AES-256 itself is not feasibly broken

    Modern Office encryption using AES-256 is cryptographically strong; examiners rely on password-guessing attacks (dictionary, rules, GPU-assisted) rather than breaking the encryption algorithm itself.

  5. What is the forensic significance of a password found in the Windows Credential Manager or DPAPI-protected storage?

    Answer: It may provide the actual password used for encrypted files, websites, or network shares without requiring cracking

    Windows Credential Manager and DPAPI often store passwords in a form recoverable with the user's account credentials, providing plaintext passwords that can directly unlock encrypted resources.

  6. During a forensic examination, an examiner discovers high-entropy data scattered in unallocated space with no file header. This most likely indicates:

    Answer: Remnants of encrypted or compressed file data from deleted files

    High entropy in unallocated space without recognizable headers typically indicates deleted encrypted or compressed file fragments that were previously allocated to protected files.

  7. What is the primary purpose of documenting the password recovery methodology in the forensic report?

    Answer: To establish the scientific validity and repeatability of the technique used, supporting admissibility of the decrypted evidence

    Documenting methodology demonstrates that the recovery process was sound, repeatable, and scientifically valid — essential for evidence admissibility and withstanding expert scrutiny in court.