ACI FTK Toolkit & Investigation Workflow Flashcards
6 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 ACI FTK Toolkit & Investigation Workflow flashcards as text
What is the purpose of creating a 'forensic image' rather than simply copying files from a suspect drive?
Answer: Forensic images capture the complete bit-for-bit state of a drive including deleted data, slack space, and unallocated areas
A forensic image is a sector-by-sector copy that preserves all data including deleted files, slack space, and unallocated regions that a simple file copy would miss.
In FTK, what does the 'Overview' tab's 'File Category' breakdown help an investigator prioritize?
Answer: High-interest file types (e.g., images, documents, executables) to focus the investigation
The File Category breakdown gives an at-a-glance count of file types across the evidence, helping investigators quickly focus on the most relevant categories like images or executables.
Why is it important to document the MD5 and SHA-1 hashes of a forensic image at the time of acquisition?
Answer: To provide a verifiable fingerprint proving the evidence has not been altered since collection
Hashes serve as a cryptographic fingerprint; any change to the evidence after acquisition will produce a different hash, proving tampering or corruption.
When using FTK to analyze a suspect's Windows machine, which registry hive contains the most recently accessed files and typed URLs?
Answer: NTUSER.DAT (user-specific hive), including RecentDocs and TypedURLs keys
The NTUSER.DAT hive for each user contains RecentDocs, TypedURLs, and other MRU (Most Recently Used) keys that record recent file access and browser activity.
What action should an ACI investigator take if they discover that a write blocker failed and the suspect drive may have been modified during acquisition?
Answer: Immediately document the incident, stop using the drive, and notify supervisors to assess evidence admissibility
Any potential evidence contamination must be immediately documented and reported so that legal counsel and supervisors can evaluate the impact on the case's admissibility.
In FTK, what is the purpose of 'bookmarking' items during an investigation?
Answer: To flag and organize significant evidence items for inclusion in reports and court presentations
Bookmarks allow investigators to tag significant files and artifacts, organizing evidence into labeled groups that can be directly exported into investigative reports.