A30-327 Exam Questions
58 real A30-327 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Data Acquisition and Preservation
Which type of evidence can be added to FTK Imager?
FTK ImagerEvidence ImportData AcquisitionFolder Contents - Question #2Data Acquisition and Preservation
To obtain protected files on a live machine with FTK Imager, which evidence item should be added?
FTK ImagerLive acquisitionEvidence collectionProtected file access - Question #3Data Acquisition and Preservation
What are three image file formats that can be read by FTK Imager? (Choose three.)
FTK Imagerforensic imaging formatsE01/raw/SafeBack formatsevidence acquisition - Question #4Data Acquisition and Preservation
Which statement is true about using FTK Imager to simultaneously create multiple images of a single source?
FTK ImagerImage Creation WizardMultiple destination jobsData acquisition - Question #5Data Acquisition and Preservation
FTK Imager allows a user to convert a Raw (dd) image into which two formats? (Choose two.)
FTK ImagerImage Format Conversiondd/Raw FormatForensic Imaging - Question #6Data Acquisition and Preservation
You are converting one image file format to another using FTK Imager. Why are the hash values of the original image and the resulting new image the same?
hash valuesimage format conversiondata integrityFTK Imager - Question #7Data Acquisition and Preservation
How can you use FTK Imager to obtain registry files from a live system?
FTK ImagerRegistry filesLive system acquisitionFile export - Question #8Data Acquisition and Preservation
Which statement is true about using FTK Imager to export a folder and its subfolders?
FTK ImagerExport functionalityFolder hierarchyData acquisition - Question #9Data Acquisition and Preservation
You used FTK Imager to create several hash list files. You view the location where the files were exported. What is the file extension type for these files?
FTK Imagerhash listsCSV exportfile formats - Question #10Data Acquisition and Preservation
You create two evidence images from the suspect's drive: suspect.E01 and suspect.001. You want to be able to verify that the image hash values are the same for suspect.E01 and susp...
Evidence Image FormatsHash VerificationRaw Image HashingForensic Imaging - Question #11Data Acquisition and Preservation
You successfully export and create a file hash list while using FTK Imager. Which three pieces of information are included in this file? (Choose three.)
File hashingFTK ImagerHash verificationMD5/SHA1 - Question #12Data Acquisition and Preservation
During the execution of a search warrant, you image a suspect drive using FTK Imager and store the Raw (dd) image files on a portable drive. Later, these files are transferred to a...
hash verificationforensic imagingimage integrityFTK Imager - Question #13Data Acquisition and Preservation
Which three items are contained in an Image Summary File using FTK Imager? (Choose three.)
Image Summary FileFTK ImagerHash VerificationDisk Imaging - Question #14Data Acquisition and Preservation
Which two image formats contain an embedded hash value for file verification? (Choose two.)
Forensic imagingHash verificationE01 EnCaseData integrity - Question #15File System Analysis
While analyzing unallocated space, you locate what appears to be a 64-bit Windows date and time. Which FTK Imager feature allows you to display the information as a date and time?
Windows FILETIME FormatUnallocated Space AnalysisFTK Imager FeaturesHex Value Conversion - Question #16File System Analysis
In which Overview tab container are HTML files classified?
HTML file classificationFile containersEvidence categorizationOverview tab - Question #17File System Analysis
When adding data to FTK, which statement about DriveFreeSpace is true?
DriveFreeSpacefile slackFTK classificationunallocated space - Question #18Artifact Analysis (e.g., Internet history, email, registry)
You are using FTK to process e-mail files. In which two areas can E-mail attachments be located? (Choose two.)
email attachmentsFTK interfaceartifact locationemail forensics - Question #19File System Analysis
In FTK, which tab provides specific information on the evidence items, file items, file status and file category?
FTK Overview tabEvidence examinationFile system propertiesForensic tool interface - Question #20Forensic Process and Best Practices
In FTK, you navigate to the Graphics tab at the Case level and you do not see any graphics. What should you do to see all graphics in the case?
FTK Graphics tabCase hierarchyDescendantsData visualization - Question #21Artifact Analysis (e.g., Internet history, email, registry)
In FTK, which two formats can be used to export an E-mail message? (Choose two.)
FTK email exportemail artifact formatsforensic tool functionalityemail preservation - Question #22File System Analysis
In FTK, when you view the Total File Items container (rather than the Actual Files container), why are there more items than files?
FTK containersarchive file handlingfile enumerationfile system analysis - Question #23Forensic Process and Best Practices
Which statement is true about Processes to Perform in FTK?
FTK ProcessingEvidence AdditionCase WorkflowProcessing Options - Question #24Data Acquisition and Preservation
What are three types of evidence that can be added to a case in FTK? (Choose three.)
FTK evidence typesdata acquisitionforensic sourcesevidence handling - Question #25Keyword Searching and Filtering
You want to search for two words within five words of each other. Which search request would accomplish this function?
proximity operatorssearch syntaxkeyword filteringw/5 operator - Question #26Keyword Searching and Filtering
You need to search for specific data that are located in a Microsoft Word document. You do not know the exact spelling of this data. Using the Index Search Options as displayed in...
Fuzzy matchingFile pattern filteringIndex search optionsKeyword searching - Question #27Keyword Searching and Filtering
You have processed a case in FTK using all the default options. The investigator supplies you with a list of 400 names in an electronic format. What is the quickest way to search u...
Indexed SearchBatch keyword searchFTK search optimizationUnallocated space searching - Question #28Keyword Searching and Filtering
Which pattern does the following regular expression recover? (\d{4})[\\]\)-](3)(\d{4})
Regular expressionsPattern matchingData format identificationRegex parsing - Question #29Forensic Process and Best Practices
You examine evidence and flag several graphic images found in different folders. You now want to bookmark these items into a single bookmark. Which tab in FTK do you use to view on...
FTK interfaceflagging evidencethumbnail viewingevidence organization - Question #30Keyword Searching and Filtering
What change do you make to the file filter shown in the exhibit in order to show only graphics with a logical size between 500 kilobytes and 10 megabytes?
file filteringfile type constraintssize-based filteringfilter UI - Question #31File System Analysis
FTK uses Data Carving to find which three file types? (Choose three.)
Data CarvingFTKFile RecoveryFile Type Signatures - Question #32Report Generation and Documentation
You are asked to process a case using FTK and to produce a report that only includes selected graphics. What allows you to display only flagged graphics?
FTK Graphic ThumbnailsFlagged Evidence DisplayReport FilteringEvidence Selection - Question #33Report Generation and Documentation
Which two options are available in the FTK Report Wizard? (Choose two.)
FTK Report WizardReport generationFile path listingFile properties - Question #34Report Generation and Documentation
Using the FTK Report Wizard, which two options are available in the List by File Path window? (Choose two.)
FTK Report WizardReport ExportList FilteringFile Path Reporting - Question #35Report Generation and Documentation
Using the FTK Report Wizard, which two options are available in the Bookmarks - A window? (Choose two.)
FTK Report WizardBookmarksGraphics ExportReport Configuration - Question #36Artifact Analysis (e.g., Internet history, email, registry)
In Registry Viewer, which steps initiate the Hex Interpreter?
Registry ViewerHex InterpreterRegistry AnalysisTool Navigation - Question #37Artifact Analysis (e.g., Internet history, email, registry)
Which data in the Registry can the Registry Viewer translate for the user? (Choose three.)
Registry analysisRegistry ViewerMRU artifactsWindows PSSP - Question #38Artifact Analysis (e.g., Internet history, email, registry)
What are two functions of the Summary Report in Registry Viewer? (Choose two.)
Registry analysisRegistry ViewerSummary ReportArtifact examination - Question #39Artifact Analysis (e.g., Internet history, email, registry)
When using Registry Viewer to view a key with 20 values, what option can be used to display only 5 of the 20 values in a report?
Registry AnalysisReport FilteringRegistry ViewerArtifact Reporting - Question #40Report Generation and Documentation
You view a registry file in Registry Viewer. You want to create a report, which includes items that you have marked "Add to Report." Which Registry Viewer option accomplishes this...
Registry artifact analysisReport generationRegistry Viewer toolForensic documentation - Question #41Artifact Analysis (e.g., Internet history, email, registry)
Which Registry Viewer function would allow you to automatically document multiple unknown user names?
registry analysisuser account documentationautomated reportingwildcard queries - Question #42Forensic Process and Best Practices
What is the purpose of the Golden Dictionary?
Password recoveryGolden DictionaryDictionary attacksForensic tools - Question #43Artifact Analysis (e.g., Internet history, email, registry)
What is the most effective method to facilitate successful password recovery?
password recoverydictionary attackforensic toolscryptanalysis - Question #44Artifact Analysis (e.g., Internet history, email, registry)
You are attempting to access data from the Protected Storage System Provider (PSSP) area of a registry. How do you accomplish this using PRTK?
PSSPNTUSER.datRegistry AnalysisPRTK - Question #45Forensic Process and Best Practices
When using PRTK to attack encrypted files exported from a case, which statement is true?
encryption decryptionfile hashingPRTKevidence integrity - Question #46Forensic Process and Best Practices
In FTK, a user may alter the alert or ignore status of individual hash sets within the active KFF. Which utility is used to accomplish this?
KFF (Known File Filter)Hash Database ManagementAlert Status ConfigurationFTK Utilities - Question #47Artifact Analysis (e.g., Internet history, email, registry)
After creating a case, the Encrypted Files container lists EFS files. However, no decrypted sub- items are present. All other necessary components for EFS decryption are present in...
EFS decryptionWindows registry artifactsSAM and system filesPassword recovery - Question #48Data Acquisition and Preservation
Which two statements are true? (Choose two.)
PRTKPassword RecoveryEFS DecryptionTool Integration - Question #49File System Analysis
When decrypting EFS files in a case, you receive the result shown in the exhibit. What is the most plausible explanation for this result?
EFS encryptionuser certificatesmulti-user file systemsdecryption failure analysis - Question #50Artifact Analysis (e.g., Internet history, email, registry)
Which two Registry Viewer operations can be conducted from FTK? (Choose two.)
registry analysisFTK capabilitiesartifact extractionreport generation