โ† All ACI Flashcard Decks

ACI FTK Toolkit & Investigation Workflow Flashcards

6 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 ACI FTK Toolkit & Investigation Workflow flashcards as text
  1. Which AccessData tool is specifically designed for decrypting files protected by popular encryption applications like BitLocker and TrueCrypt?

    Answer: PRTK (Password Recovery Toolkit)

    PRTK is AccessData's dedicated password recovery tool that supports dictionary, hybrid, and brute-force attacks against encrypted files and full-disk encryption.

  2. When adding evidence to an FTK case, what is the difference between a 'Physical Drive' and 'Logical Drive' evidence type?

    Answer: Physical Drive acquires raw sector data including unallocated space; Logical Drive captures only allocated file system data

    Physical drive acquisition captures the entire raw disk including unallocated, slack, and deleted file space, while logical acquisition only captures active file system contents.

  3. In FTK's email analysis module, what does examining the 'Email Thread' view help an investigator determine?

    Answer: The chronological conversation flow between participants including deleted replies

    The email thread view reconstructs conversations in chronological order, helping investigators understand the full communication context including replies that may have been deleted.

  4. What is the significance of 'slack space' in digital forensics investigations using FTK?

    Answer: It is the area between the end of a file and the end of its allocated cluster, which may contain remnant data from previously deleted files

    File slack space exists because files rarely fill their allocated clusters exactly, leaving remnant data from overwritten files that can be recovered as evidence.

  5. Which FTK feature allows an investigator to search for specific text patterns across all evidence, including inside documents and emails?

    Answer: Full-text index search with live search

    FTK's full-text indexing and live search allow investigators to search for keywords, phrases, and regex patterns across all processed evidence simultaneously.

  6. During an FTK investigation, an analyst notices a file with a creation date earlier than the operating system installation date. What does this likely indicate?

    Answer: The file may have been backdated or copied from another system to falsify timestamps

    A file predating the OS installation is anomalous and may indicate timestamp manipulation (timestomping) to conceal when the file was actually placed on the system.

ACI FTK Toolkit & Investigation Workflow Flashcards โ€” ACI Study Cards with Answers