ADC Data Analysis & Statistical Methods Flashcards
6 cards from real ADC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 ADC Data Analysis & Statistical Methods flashcards as text
What is the primary purpose of hash value analysis in AccessData FTK?
Answer: To verify file integrity and identify known files
Hash values like MD5 and SHA-1 uniquely fingerprint files, allowing examiners to verify that evidence has not been altered and to match files against known hash sets.
Which method in FTK identifies files that have been intentionally renamed to hide their true type?
Answer: File signature vs. extension mismatch detection
FTK compares the file's internal signature (magic bytes) against its extension, flagging mismatches that indicate deliberate obfuscation.
What does 'data carving' refer to in digital forensics with AccessData?
Answer: Recovering files from unallocated disk space based on file signatures
Data carving reconstructs files from raw disk sectors by locating known file headers and footers, even without a valid file system entry.
What is the analytical value of examining MFT (Master File Table) records in FTK?
Answer: They contain detailed metadata including file creation, modification, and access timestamps
The NTFS MFT stores a record for every file including MAC (Modified, Accessed, Created) timestamps that are critical for timeline reconstruction.
What type of analysis examines patterns in file access times within AccessData tools?
Answer: Temporal forensic analysis
Temporal forensic analysis correlates file timestamps across the evidence set to reconstruct the chronological sequence of user and system activity.
Which FTK feature helps analysts identify duplicate files across an evidence set?
Answer: MD5/SHA hash comparison
FTK computes hash values for every file and groups identical hashes together, enabling rapid deduplication and identification of copied files.