Advanced Techniques & Methods Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Advanced Techniques & Methods flashcards as text
When examining a suspect's cloud storage artifacts in Windows, which local artifacts would most directly evidence files synced to/from a cloud service like Dropbox?
Answer: Sync client database files, LNK files, and shellbag entries referencing cloud-synced paths
Cloud sync clients maintain local SQLite/database files tracking sync activity, and Windows artifacts like LNK files and shellbags record access to cloud-synced folder paths.
A forensic examiner needs to prove a specific USB device was connected to a suspect's computer at a given time. Which Windows artifact provides the strongest evidence?
Answer: SYSTEM registry hive entries under USBSTOR with first/last connection timestamps
The USBSTOR key in the SYSTEM registry records device identifiers, serial numbers, and connection timestamps for every USB storage device ever connected to the system.
During mobile device forensics integrated with FTK, what does a 'logical acquisition' capture compared to a 'physical acquisition'?
Answer: Logical captures only the active file system; physical captures the full raw storage including deleted data
Logical acquisition retrieves the active file system through device APIs, while physical acquisition images the raw NAND flash storage, including deleted data and unallocated space.
When analyzing Windows Event Logs in FTK, which Event ID is most significant for proving interactive user logon to a system?
Answer: Event ID 4624 with Logon Type 2 or 10
Event ID 4624 records successful logons; Logon Type 2 indicates interactive (console) logon and Type 10 indicates remote interactive (RDP) logon, both proving direct user access.
In FTK, when performing keyword searches across evidence, what advantage does an indexed search provide over a live search?
Answer: Indexed search is significantly faster because terms are pre-processed into a searchable index during evidence processing
FTK builds a full-text index during processing, allowing indexed searches to complete in seconds by querying the pre-built index rather than scanning raw evidence data.
What is the forensic purpose of analyzing the Windows Recycle Bin artifacts ($I and $R files) on a NTFS volume?
Answer: To determine the original file path, deletion time, and recover the content of deleted files
$I files store metadata (original path and deletion timestamp) while $R files store the actual deleted file content, together providing complete evidence of deliberate file deletion.
When an ACE examiner needs to validate that a forensic tool produced accurate results, which best practice should be employed?
Answer: Use a validated test image with known artifacts and verify the tool correctly identifies them
Using a known test image with documented artifacts (such as those from NIST's CFReDS) and verifying the tool correctly identifies them is the accepted scientific method for tool validation.