Technology & Tools Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technology & Tools flashcards as text
FTK's 'Cerberus' malware triage feature analyzes executables by:
Answer: Performing static analysis using heuristics and comparing against known malware signatures
Cerberus performs static code analysis and behavioral heuristics on executables within FTK without executing them, flagging suspicious characteristics.
When acquiring a RAM image from a live Windows system with FTK Imager, which type of data can be recovered?
Answer: Running processes, network connections, encryption keys, and unencrypted content of open files
A live RAM capture contains volatile artifacts including active processes, open network sockets, decrypted data in memory, and cryptographic key material.
An examiner images a drive and gets an MD5 of 'A1B2C3...' but after analysis the hash recomputed from the image is 'D4E5F6...'. What does this indicate?
Answer: The image was altered or corrupted after acquisition, raising integrity concerns
A hash mismatch between pre- and post-acquisition values indicates the image no longer matches the original and its evidentiary integrity is compromised.
In FTK, what is the role of the 'Summation' integration (or FTK's Legal export features)?
Answer: Exports case data and evidence sets in formats suitable for legal review platforms and eDiscovery workflows
FTK supports export to eDiscovery and legal review platforms, formatting bookmarked evidence, reports, and metadata for litigation support workflows.
Which characteristic of NTFS file system is particularly valuable during forensic investigation for tracking file activity?
Answer: NTFS maintains a $LogFile and $UsnJrnl that record file system transactions and changes
The NTFS $UsnJrnl (Update Sequence Number Journal) logs file creation, modification, deletion, and renaming events, providing a forensic history of file activity.
When FTK's indexing process is complete, what capability does the resulting index primarily provide?
Answer: Near-instant full-text keyword searches across all indexed evidence without rescanning raw data
The FTK index pre-processes all text content from evidence so searches query the index rather than raw data, returning results in seconds regardless of evidence size.
Which AccessData FTK feature allows examiners to categorize and tag files during review for reporting purposes?
Answer: Bookmarking
Bookmarking allows examiners to label, annotate, and group files of interest so they can be easily referenced and included in the final case report.