Digital Forensics and Evidence Flashcards
7 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Forensics and Evidence flashcards as text
What is the purpose of a MD5 or SHA-256 hash in digital forensics?
Answer: To verify that a forensic copy is identical to the original evidence
Cryptographic hashes create a unique digital fingerprint of data; matching hashes between original and copy confirm that no bits were altered during acquisition.
An examiner discovers that a suspect used a virtual machine (VM) for financial transactions. Where is the most valuable forensic data typically found?
Answer: The VM's .vmdk or .vhd disk image file on the host system
The virtual disk image file (.vmdk, .vhd) contains the entire guest OS file system and can be mounted and examined like a physical drive.
In network forensics, what does 'pcap' data contain?
Answer: Full packet captures of network traffic including payloads
PCAP (Packet Capture) files store raw network packets, allowing examiners to reconstruct sessions, recover transmitted files, and identify communications.
When examining browser history for evidence of fraud, which artifact reveals sites visited even after history was manually cleared in most Chromium-based browsers?
Answer: DNS cache entries and browser cache thumbnails
DNS cache and thumbnail/favicon databases may retain visited site evidence even when browsing history is manually deleted from within the browser.
A suspect claims a financial spreadsheet was never modified after its creation date. What forensic technique can refute or support this claim?
Answer: Analyzing MFT timestamps, file metadata, and shadow copy versions
NTFS MFT timestamps, embedded document metadata, and Volume Shadow Copies can collectively establish the true modification history of a file.
Which of the following best describes 'file slack space' in digital forensics?
Answer: The unused space between the end of a file's data and the end of its last allocated cluster
File slack is the area between the end of a file's logical content and the end of its last storage cluster, which may contain remnants of previously stored data.
What is the forensic significance of the Windows 'LNK' (shortcut) files?
Answer: They can reveal the original path, creation date, and MAC address of files accessed even from removed devices
Windows LNK files record metadata about the target file including timestamps, volume serial number, and network share details, revealing access to files on now-absent drives.