โ† All ACE Flashcard Decks

Digital Forensic Principles & Methodologies Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensic Principles & Methodologies flashcards as text
  1. Which of the following best describes the forensic principle of 'Locard's Exchange Principle' as applied to digital environments?

    Answer: Every interaction between a suspect and a digital system leaves traces on both

    Locard's Exchange Principle states that every contact leaves a trace, meaning digital interactions leave artifacts on both the system accessed and the actor's system.

  2. In Windows forensics, what information can be extracted from Prefetch files (.pf)?

    Answer: Evidence of program execution including last run time and run count

    Windows Prefetch files record the name of executed applications, the number of times they were run, and the last execution timestamp.

  3. An examiner is reviewing a forensic image and notices that the MFT entry for a file shows it has been deleted, but the data clusters have not been overwritten. What can the examiner do?

    Answer: The file can be recovered using data carving or MFT analysis since the data clusters are intact

    When a file is deleted, the MFT entry is marked as available and clusters are de-allocated but not immediately overwritten, making recovery possible through carving or MFT analysis.

  4. What is 'anti-forensics' in the context of digital investigations?

    Answer: Techniques used to thwart or complicate forensic analysis of digital evidence

    Anti-forensics encompasses techniques such as encryption, data wiping, timestamp manipulation, and steganography used to hinder forensic investigations.

  5. Which type of forensic examination involves analyzing network traffic captures to reconstruct communications and activities?

    Answer: Network forensics

    Network forensics involves capturing and analyzing network traffic (pcap files) to reconstruct events, identify communications, and detect intrusions.

  6. When an ACE examiner testifies as an expert witness, what is the primary standard used by federal courts to evaluate the admissibility of expert testimony?

    Answer: Daubert standard

    The Daubert standard requires federal courts to evaluate whether expert testimony is based on sufficient facts, reliable methodology, and is relevant to the case.

  7. Which FTK feature allows an examiner to index and search the full text content of files across an entire forensic image?

    Answer: Full Text Index (FTI)

    FTK's Full Text Index pre-indexes all text content in a case so examiners can perform fast keyword searches across all files in the forensic image.