Technology & Tools Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technology & Tools flashcards as text
What is the primary function of AccessData's Password Recovery Toolkit (PRTK)?
Answer: Recovers or attacks passwords protecting files and encrypted volumes
PRTK uses dictionary, rule-based, and brute-force attacks to recover passwords from protected files including documents, archives, and encrypted containers.
Which file format does FTK Imager use to create a proprietary AccessData forensic image?
Answer: AD1 (AccessData Image)
AD1 is AccessData's native logical image format, while E01 is EnCase's format; FTK Imager also supports E01 and DD, but AD1 is the AccessData proprietary format.
When performing a forensic acquisition, why is it important to document the hash value both before and after imaging?
Answer: To prove the forensic copy is an exact, unaltered duplicate of the original
Matching hash values before and after imaging mathematically demonstrates the copy is bit-for-bit identical, establishing forensic integrity.
In FTK, the 'Compound File' processing option is used to:
Answer: Extract contents of containers like ZIP files, PST files, and compound documents for individual review
Processing compound files causes FTK to open container formats (archives, email stores, Office documents with embedded objects) and index their internal contents.
Which AccessData utility is designed to triage and acquire evidence from mobile devices in the field?
Answer: MPE+ (Mobile Phone Examiner Plus)
MPE+ is AccessData's dedicated mobile forensics tool for acquiring and analyzing data from smartphones and tablets.
A forensic examiner discovers a volume encrypted with BitLocker. Which AccessData approach is most applicable to access the data?
Answer: Supply the recovery key or user password through PRTK or FTK's decryption support
FTK and PRTK can decrypt BitLocker volumes when the recovery key or password is provided, enabling analysis of the decrypted contents.
What is 'slack space' in the context of digital forensics?
Answer: The area between the end of a file's logical size and the end of its last allocated cluster
Slack space is the remnant space in the last cluster allocated to a file, which may contain fragments of previously deleted data.