โ† All ACE Flashcard Decks

Evidence Acquisition & Preservation Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Evidence Acquisition & Preservation flashcards as text
  1. What does 'verification' mean in the context of a forensic image created with FTK Imager?

    Answer: Re-hashing the completed image and comparing it to the hash computed during acquisition

    Verification re-computes the hash of the finished image and compares it to the acquisition-time hash to confirm the image is an exact, unaltered copy.

  2. An investigator is responding to a ransomware incident. Which evidence should be collected BEFORE isolating the infected system from the network?

    Answer: Network connections, active processes, and running memory to identify encryption keys

    Active network connections and RAM may contain the ransomware's encryption keys or C2 communication data that disappears upon network isolation or shutdown.

  3. Which file system artifact is MOST useful for proving a USB drive was connected to a Windows system even if the drive has been removed?

    Answer: USBSTOR registry keys and Windows Event Log entries on the host

    USBSTOR registry entries and Event Log records on the host system log device connection details (serial number, timestamps) independent of the physical USB drive.

  4. What is 'sparse acquisition' in the context of mobile device forensics?

    Answer: Imaging only non-empty, allocated regions of storage to reduce image size

    Sparse acquisition skips empty (zeroed) sectors and records only blocks with actual data, significantly reducing image size for large-capacity devices.

  5. Why is timestamping an evidence collection log with UTC rather than local time considered best practice?

    Answer: UTC eliminates ambiguity from daylight saving time changes and time zone differences across jurisdictions

    UTC is a universal reference that avoids the confusion of daylight saving adjustments and cross-jurisdiction time zone discrepancies in multi-location investigations.

  6. During evidence packaging, which labeling information is LEAST critical to include on the evidence bag?

    Answer: The retail purchase price of the device

    The retail price of a device has no bearing on chain of custody or evidence identification; all other fields are required for proper documentation.

  7. What is the significance of the 'hash set' feature in FTK during evidence processing?

    Answer: It compares file hashes against known databases (e.g., NSRL) to quickly identify or exclude known files

    Hash sets allow FTK to flag known-good files (e.g., OS files via NSRL) or known-bad files (e.g., CSAM hashes), dramatically narrowing the scope of manual review.