Tool Proficiency & Analysis Techniques Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Tool Proficiency & Analysis Techniques flashcards as text
Which AccessData tool is specifically designed to perform distributed processing of forensic cases across multiple machines to speed up analysis?
Answer: Enterprise with Processing Engines
FTK Enterprise with Processing Engines allows distributed forensic processing across multiple machines to handle large case volumes faster.
When carving files from unallocated space in FTK, which two values define the boundaries of a carved file?
Answer: Header signature and footer signature
File carving identifies files by locating known file type header signatures and their corresponding footer signatures in raw disk data.
In FTK's email analysis, which artifact from a Microsoft Outlook PST file is most valuable for establishing a timeline of suspect communications?
Answer: Individual email sent and received timestamps stored in the message properties
Individual message properties within a PST store precise sent and received timestamps that are more reliable for timeline reconstruction than file system metadata.
An examiner uses FTK to analyze a FAT32 volume and notices directory entries with a first byte of 0xE5. What does this signify?
Answer: A deleted directory entry that may still have recoverable data
In FAT file systems, a 0xE5 value in the first byte of a directory entry indicates the file was deleted, though its cluster chain may still hold recoverable data.
During a FTK examination, an examiner identifies files with very high entropy values. What is the MOST likely explanation?
Answer: The files are compressed or encrypted
High entropy values indicate data that is highly random, which is characteristic of encrypted or compressed files where patterns are intentionally obscured.
When using FTK Imager's 'Capture Memory' function, what type of file is created that an examiner would later load into a memory analysis tool?
Answer: A raw .mem or .dmp memory dump file
FTK Imager's Capture Memory function creates a raw memory dump file (.mem or .dmp) containing the full contents of physical RAM at capture time.
Which technique does AccessData's DNA (Distributed Network Attack) use to accelerate password recovery that PRTK alone cannot leverage?
Answer: Distributing cracking tasks across multiple networked computers simultaneously
DNA distributes password recovery workloads across many networked machines, dramatically increasing throughput compared to single-machine PRTK cracking.