โ† All ACE Flashcard Decks

Digital Forensic Principles & Methodologies Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensic Principles & Methodologies flashcards as text
  1. When acquiring a forensic image of a hard drive, the investigator calculates an MD5 hash before and after the process. The hashes match. What does this confirm?

    Answer: The acquisition was completed without altering the original data

    Matching pre- and post-acquisition hashes confirm that the original evidence was not modified during the imaging process.

  2. Which file system artifact stores the last eight files deleted from the Windows desktop or Windows Explorer?

    Answer: The Recycle Bin ($I and $R files)

    The Windows Recycle Bin stores deleted files as $R (content) and $I (metadata) pairs until they are permanently deleted.

  3. In AccessData FTK, what does the 'Known File Filter' (KFF) feature help an examiner do?

    Answer: Identify and filter known good and known bad files by hash values

    The KFF compares file hashes against databases of known good (OS/application) and known bad (contraband) files to quickly prioritize evidence.

  4. What is the purpose of documenting the 'chain of custody' for digital evidence?

    Answer: To track who had possession of evidence and when, ensuring its integrity

    Chain of custody documentation ensures evidence integrity by recording every person who handled the evidence and when, defending against tampering allegations.

  5. During examination, an investigator finds a file in unallocated disk space. What technique was most likely used to recover it?

    Answer: Data carving

    Data carving recovers files from unallocated space by searching for known file headers and footers without relying on file system structures.

  6. A forensic examiner is analyzing Windows artifacts and wants to determine what USB devices were previously connected to a system. Which registry hive should they examine?

    Answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR

    The USBSTOR registry key records details about USB storage devices that have been connected to the system, including device identifiers.

  7. What is the main difference between logical and physical forensic acquisition of a hard drive?

    Answer: Logical acquisition is faster and captures only active file system data; physical captures every bit including deleted and slack space

    Logical acquisition captures only the visible file system contents, while physical acquisition copies every bit of the drive including deleted files, slack space, and unallocated areas.