Data Acquisition and Duplication Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Data Acquisition and Duplication flashcards as text
What is the Host Protected Area (HPA) and why is it forensically significant?
Answer: A hidden drive region invisible to the OS that may contain concealed data
The HPA is a reserved area at the end of a drive that the OS cannot see; suspects may hide data there, and standard imaging tools miss it unless configured to access it.
During network-based forensic acquisition, which protocol is commonly used to stream a disk image over the network?
Answer: netcat or dcfldd piped over SSH
Forensic examiners commonly pipe dd or dcfldd output through netcat or SSH to transfer disk images over a network to a remote storage server.
Which hash algorithm is currently recommended by NIST for forensic image verification due to collision resistance concerns with MD5?
Answer: SHA-256
NIST recommends SHA-256 (or stronger) for forensic integrity verification because MD5 and SHA-1 are vulnerable to collision attacks.
An examiner acquires a drive and calculates an MD5 hash that differs from the hash taken by the first responder. What is the MOST likely conclusion?
Answer: The evidence was altered or the chain of custody was broken between acquisitions
A hash mismatch between acquisition points indicates that data changed, suggesting evidence tampering or a broken chain of custody.
What is 'write blocking' and which layer does a software write blocker operate at?
Answer: Intercepts write commands via OS driver or API interception before they reach the drive
Software write blockers intercept OS-level write commands (via drivers or system call hooks) before they reach the storage device, preventing data modification during examination.
When imaging a solid-state drive (SSD), which characteristic makes forensic acquisition more challenging than with HDDs?
Answer: Wear leveling and TRIM commands can overwrite deleted data, reducing recoverability
SSD controllers use wear leveling to distribute writes, and TRIM actively zeroes deleted blocks, making traditional deleted-data recovery difficult on SSDs.
Which tool is specifically designed for acquiring volatile memory (RAM) on a live Windows system?
Answer: WinPmem
WinPmem is an open-source Windows memory acquisition tool that dumps physical RAM to a file for forensic analysis of volatile data.