โ† All CHFI Flashcard Decks

Data Acquisition and Duplication Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Acquisition and Duplication flashcards as text
  1. What is the Host Protected Area (HPA) and why is it forensically significant?

    Answer: A hidden drive region invisible to the OS that may contain concealed data

    The HPA is a reserved area at the end of a drive that the OS cannot see; suspects may hide data there, and standard imaging tools miss it unless configured to access it.

  2. During network-based forensic acquisition, which protocol is commonly used to stream a disk image over the network?

    Answer: netcat or dcfldd piped over SSH

    Forensic examiners commonly pipe dd or dcfldd output through netcat or SSH to transfer disk images over a network to a remote storage server.

  3. Which hash algorithm is currently recommended by NIST for forensic image verification due to collision resistance concerns with MD5?

    Answer: SHA-256

    NIST recommends SHA-256 (or stronger) for forensic integrity verification because MD5 and SHA-1 are vulnerable to collision attacks.

  4. An examiner acquires a drive and calculates an MD5 hash that differs from the hash taken by the first responder. What is the MOST likely conclusion?

    Answer: The evidence was altered or the chain of custody was broken between acquisitions

    A hash mismatch between acquisition points indicates that data changed, suggesting evidence tampering or a broken chain of custody.

  5. What is 'write blocking' and which layer does a software write blocker operate at?

    Answer: Intercepts write commands via OS driver or API interception before they reach the drive

    Software write blockers intercept OS-level write commands (via drivers or system call hooks) before they reach the storage device, preventing data modification during examination.

  6. When imaging a solid-state drive (SSD), which characteristic makes forensic acquisition more challenging than with HDDs?

    Answer: Wear leveling and TRIM commands can overwrite deleted data, reducing recoverability

    SSD controllers use wear leveling to distribute writes, and TRIM actively zeroes deleted blocks, making traditional deleted-data recovery difficult on SSDs.

  7. Which tool is specifically designed for acquiring volatile memory (RAM) on a live Windows system?

    Answer: WinPmem

    WinPmem is an open-source Windows memory acquisition tool that dumps physical RAM to a file for forensic analysis of volatile data.