โ† All CHFI Flashcard Decks

Data Acquisition and Duplication Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Acquisition and Duplication flashcards as text
  1. What is the Device Configuration Overlay (DCO) and how does it differ from the HPA?

    Answer: DCO is configured by the manufacturer or OEM to limit drive capacity; HPA is user-configurable

    The DCO is typically set by manufacturers to standardize drive capacity across product lines, while the HPA can be set by the user or OS to hide data; both are invisible to the OS.

  2. A forensic examiner is acquiring a drive from a Mac with Apple Silicon (M1/M2). What is a key challenge compared to Intel-based Macs?

    Answer: Target Disk Mode is not available; acquisition requires OS-level tools or JTAG methods

    Apple Silicon Macs removed Target Disk Mode, making traditional hardware-based acquisition impossible and requiring alternative methods like using Apple Configurator or specialized JTAG hardware.

  3. Which dcfldd command option generates a hash of the acquired image simultaneously during the imaging process?

    Answer: hashlog=

    dcfldd's 'hashlog=' option writes a running hash (MD5 or SHA-1) to a specified log file as the image is being created, enabling simultaneous acquisition and verification.

  4. What is 'forensic soundness' in the context of data acquisition?

    Answer: Ensuring the acquisition process does not alter original evidence and can be independently verified

    Forensic soundness means the acquisition method preserves original evidence without modification and produces results that can be independently repeated and verified.

  5. When creating a forensic image of a RAID array, what is the RECOMMENDED approach?

    Answer: Image each individual disk separately, then reassemble the RAID virtually in analysis software

    Imaging each disk individually and then using forensic software to virtually reconstruct the RAID ensures the original disks are not modified and allows flexible analysis.

  6. What is the significance of 'slack space' in forensic data acquisition?

    Answer: Slack space between the end of a file and the end of its last cluster may contain remnants of previously deleted data

    File system slack (RAM slack + drive slack) occupies the space between a file's logical end and its allocated cluster boundary, which may contain overwritten fragments of old data.

  7. A hardware write blocker fails to initialize with a specific NVMe SSD. What is the BEST alternative to preserve evidence integrity?

    Answer: Boot the suspect machine from a trusted forensic Linux live CD with software write blocking enabled

    Booting from a trusted forensic live environment (e.g., CAINE or Tails with forensic mode) enables software write blocking for interfaces where hardware write blockers are not yet available.