← All CHFI Flashcard Decks

Data Acquisition and Duplication Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Data Acquisition and Duplication flashcards as text
  1. What is the primary purpose of using 'segment files' (e.g., E01.E01, E01.E02...) during forensic acquisition?

    Answer: To accommodate file system size limits and enable splitting across multiple storage media

    Forensic image segmentation splits large images into manageable chunks to work within file system limitations (e.g., FAT32's 4GB limit) or to span multiple storage devices.

  2. Which of the following scenarios REQUIRES a live acquisition rather than a static (dead-box) acquisition?

    Answer: A running database server with encrypted volumes that will lock on shutdown

    Encrypted volumes are only accessible while the system is running and the keys are loaded in memory; shutting down would lock the encrypted data.

  3. In FTK Imager, what does the 'Verify images after they are created' option do?

    Answer: Reads the completed image and recalculates the hash to confirm it matches the acquisition hash

    FTK Imager's post-acquisition verification reads the completed image file and recalculates its hash, confirming it matches the hash computed during acquisition.

  4. What is 'remote forensic acquisition' and what network tool is commonly used to facilitate it?

    Answer: Acquiring evidence from a remote computer using an agent (e.g., EnCase Enterprise) deployed on the target

    Remote forensic acquisition uses an agent (such as EnCase Enterprise's SAFE server or F-Response) deployed on the target machine to allow an examiner to image it across the network.

  5. Which acquisition order principle, based on volatility, should guide what is collected FIRST during live forensic response?

    Answer: CPU registers and cache, then RAM, then swap space, then disk

    The order of volatility (RFC 3227) dictates collecting the most transient data first: CPU/cache → RAM → swap → network state → running processes → disk → archival media.

  6. When acquiring a mobile device using Cellebrite UFED, what does a 'physical extraction' provide compared to a 'logical extraction'?

    Answer: Physical extraction dumps the raw flash memory, recovering deleted data and system areas invisible to logical tools

    Physical extraction accesses the raw NAND flash memory, enabling recovery of deleted files and data in unallocated space that a logical extraction (which uses the device's own APIs) cannot access.

  7. What is 'chain of custody' documentation required to include for a forensic image to be admissible in court?

    Answer: Identity of each person who handled the evidence, dates/times of transfer, and condition of evidence at each transfer

    Chain of custody records must document every person who handled the evidence, when transfers occurred, and the evidence's condition, establishing an unbroken accountability trail from collection to court.