โ† All ACFE Flashcard Decks

Digital Forensics and Evidence Flashcards

7 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensics and Evidence flashcards as text
  1. What is the primary purpose of a write blocker in digital forensics?

    Answer: To prevent any data from being written to the evidence drive during acquisition

    A write blocker prevents the forensic tool from altering the evidence drive by blocking all write commands while allowing read operations.

  2. Which file system artifact is most useful for identifying when a file was deleted on a Windows NTFS volume?

    Answer: The $Recycle.Bin folder and $I files

    The $Recycle.Bin folder stores $I files (index files) that contain the original path and deletion timestamp for each deleted file.

  3. In the context of email fraud investigations, what does 'email header analysis' primarily reveal?

    Answer: The routing path and originating server of a message

    Email headers contain 'Received' fields that trace the message's path through mail servers, helping identify the true originating IP address.

  4. A fraud examiner recovers a suspect's smartphone. Which extraction method yields the most comprehensive data, including deleted records?

    Answer: Physical extraction

    Physical extraction creates a bit-for-bit image of the device's memory chip, allowing recovery of deleted data and unallocated space artifacts.

  5. What does 'MAC times' refer to in digital forensics?

    Answer: Modified, Accessed, and Created/Changed timestamps on files

    MAC times (Modified, Accessed, Changed/Created) are file system metadata timestamps that help establish a timeline of file activity.

  6. Which of the following best describes 'steganography' as it relates to fraud investigations?

    Answer: Hiding data within innocuous files such as images or audio

    Steganography conceals secret data within ordinary-looking files, which fraudsters may use to covertly transfer stolen information.

  7. During a forensic investigation of cloud storage, which legal instrument is typically required to compel a US-based cloud provider to produce user data?

    Answer: A search warrant or court order under the Stored Communications Act (SCA)

    The Stored Communications Act governs law enforcement access to electronic communications stored by third-party providers, generally requiring a warrant or court order.