← All ACE Flashcard Decks

Evidence Acquisition & Preservation Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Evidence Acquisition & Preservation flashcards as text
  1. What is the primary reason an examiner creates both MD5 and SHA-1 hashes for a forensic image?

    Answer: Dual hashing provides defense against hash collision attacks and strengthens integrity proof

    Using two independent algorithms makes it computationally infeasible for an attacker to craft a collision that matches both, strengthening admissibility arguments.

  2. Which cloud acquisition scenario presents the greatest legal complexity for a forensic examiner?

    Answer: Obtaining data directly from a cloud provider's servers across international jurisdictions

    Cross-border cloud data requests require compliance with international laws (e.g., GDPR, MLAT treaties), making them legally complex beyond domestic warrant authority.

  3. In FTK, what is the function of 'evidence processing' after an image is added?

    Answer: It indexes file content, expands containers, and performs hash lookups for rapid analysis

    Evidence processing in FTK extracts metadata, indexes text, cracks common hashes, expands archives, and carves deleted files to prepare evidence for analysis.

  4. Which of the following correctly describes the order of volatility from MOST to LEAST volatile?

    Answer: CPU registers → RAM → network state → hard disk

    CPU registers and cache are the most volatile, followed by RAM, network state, then persistent storage like hard disks and optical media.

  5. A suspect uses a portable operating system (e.g., Tails OS) booted from USB. How does this affect forensic evidence on the host machine's hard drive?

    Answer: The host drive typically contains no artifacts from the session since writes go to RAM or the USB

    Privacy-focused live OS distributions like Tails route all writes to RAM, leaving no forensic artifacts on the host hard drive after shutdown.

  6. What is 'selective imaging' and when is it appropriate?

    Answer: Acquiring specific files or folders rather than the entire drive, typically used when a full image is legally or logistically impractical

    Selective imaging targets specific data (e.g., documents folder) and is used when a full disk image is impractical, though it sacrifices unallocated space recovery.

  7. Which step must be performed before disconnecting a running server to prevent evidence loss?

    Answer: Document and capture volatile system state including running processes and network connections

    Before powering down a running server, examiners must document volatile evidence (processes, connections, logged-in users) that will not survive a shutdown.