← All ACI Flashcard Decks

ACI Network Forensics & Incident Response Flashcards

6 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 ACI Network Forensics & Incident Response flashcards as text
  1. Which artifact in FTK is used to identify previously connected USB devices on a Windows system?

    Answer: USBSTOR registry key under HKLM\SYSTEM

    The USBSTOR registry key records the device class, serial number, and first/last connection times for every USB storage device ever connected.

  2. During a network forensics case, an investigator discovers outbound traffic on port 443 to unusual IP addresses at 3 AM daily. What is the most likely interpretation?

    Answer: Scheduled malware beaconing or data exfiltration

    Regular outbound HTTPS traffic at non-business hours to unusual IPs is a strong indicator of scheduled malware activity such as beaconing or automated exfiltration.

  3. What is the role of a 'network baseline' in an incident response investigation?

    Answer: Normal traffic patterns used to identify anomalous activity during an incident

    A network baseline establishes what normal traffic looks like so that anomalies—potential indicators of compromise—can be detected by comparison.

  4. Which FTK feature allows an investigator to automatically flag files that match known malware hash values?

    Answer: Known File Filter (KFF) with hash sets

    FTK's Known File Filter compares file hashes against NSRL and custom hash sets to automatically flag known malicious files.

  5. An investigator needs to determine if a suspect accessed a specific website on a corporate machine. Which artifact provides the most reliable evidence?

    Answer: Temporary internet files and browser history cache

    Browser cache and history files contain timestamped records of visited URLs, cached content, and session data, providing reliable evidence of web access.

  6. During an incident response, what does 'dwell time' refer to?

    Answer: The length of time an attacker remains undetected within a network

    Dwell time measures how long a threat actor operated undetected inside a network between initial compromise and discovery, a key metric in breach assessments.