Technology & Tools Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technology & Tools flashcards as text
Which FTK feature allows examiners to view only files matching specific criteria such as file type, date range, or hash value without altering the case data?
Answer: Filter Manager
Filter Manager in FTK lets examiners apply criteria-based filters to narrow the file view without modifying underlying evidence.
In AccessData FTK, what is the purpose of the 'Known File Filter' (KFF) database?
Answer: Identifies and excludes known system files or flags known contraband hashes
KFF compares file hashes against known libraries to either ignore benign OS files or flag files matching known contraband hash sets.
When imaging a suspect SSD with TRIM support enabled, which concern is most critical for a forensic examiner?
Answer: TRIM can cause the OS to zero-out deleted blocks, permanently destroying recoverable data
TRIM instructs the SSD controller to erase blocks associated with deleted files, which can make carved data unrecoverable if the drive is powered on.
Which AccessData tool is specifically designed for live memory acquisition and analysis of a running system?
Answer: FTK (Memory Analysis module)
FTK's memory analysis module, combined with FTK Imager's memory capture capability, supports live RAM acquisition and subsequent analysis within FTK.
A forensic examiner uses FTK Imager to create an image but the destination drive runs out of space mid-acquisition. What is the best immediate action?
Answer: Continue imaging to another drive by splitting the image
FTK Imager supports segmented/split image output, so the examiner should configure segment sizes to span multiple destinations or target a larger drive.
What does 'write blocking' accomplish when used during forensic imaging?
Answer: Stops any write operations from reaching the evidence drive, preserving its integrity
A write blocker intercepts write commands sent to the evidence drive, ensuring the original media remains forensically unaltered.
In FTK's evidence processing options, what does enabling 'Data Carving' accomplish?
Answer: Recovers files based on file signatures from unallocated or slack space
Data carving scans raw storage for known file headers and footers to reconstruct files even when the file system no longer references them.