Advanced Techniques & Methods Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Advanced Techniques & Methods flashcards as text
When analyzing Windows Registry hives in FTK, which hive contains recently accessed files and user-specific application settings?
Answer: NTUSER.DAT
NTUSER.DAT is the per-user registry hive stored in each user's profile directory and contains MRU lists, recently accessed documents, and user-specific settings.
In FTK Imager, what is the significance of creating both an E01 image and a separate hash log file?
Answer: The hash log provides an independent record to verify image integrity at any time
A separate hash log provides an auditable, independent record of the source and image hashes, allowing verification of evidence integrity throughout the case lifecycle.
What is 'prefetch' analysis used for in a Windows forensic investigation?
Answer: Determining which applications were executed and when on a Windows system
Windows Prefetch files (.pf) record application execution data including run count and last run time, proving program execution even after the executable is deleted.
A forensic examiner needs to analyze SQLite databases found on a mobile device backup. Which FTK capability supports this?
Answer: FTK's built-in SQLite viewer and data extraction tools
FTK includes a SQLite viewer that can parse and display database contents from mobile app databases such as SMS, contacts, and browser history stores.
When examining LNK (shortcut) files during a Windows investigation, what type of evidence can they provide?
Answer: Evidence of file access including original file path, MAC times, and volume serial number
LNK files retain metadata about the target file including original path, timestamps, volume serial number, and MAC address, even if the target file is deleted.
What does 'slack space' analysis reveal in a forensic examination?
Answer: Remnants of previously stored data between the end of a file and the end of its allocated cluster
Slack space is the unused area between a file's logical end and the end of its last allocated cluster, which may contain fragments of previously deleted data.
During analysis of a suspect's web browser history in FTK, which artifact would best prove a specific URL was visited at a precise time?
Answer: Timestamped entries in the browser's history SQLite database
Modern browsers store visit history in SQLite databases with precise timestamps, providing direct evidence of URL visits with date and time.