A30-327 · Question #2
To obtain protected files on a live machine with FTK Imager, which evidence item should be added?
The correct answer is B. currently booted drive. Option B is correct because FTK Imager can access protected or locked files on a running system by adding the currently booted drive as an evidence item - this lets the tool read files that the OS would normally lock or restrict, since the drive is being accessed at a lower…
Question
Options
- Aimage file
- Bcurrently booted drive
- Cserver object settings
- Dprofile access control list
How the community answered
(28 responses)- A4% (1)
- B79% (22)
- C11% (3)
- D7% (2)
Explanation
Option B is correct because FTK Imager can access protected or locked files on a running system by adding the currently booted drive as an evidence item - this lets the tool read files that the OS would normally lock or restrict, since the drive is being accessed at a lower level while the system is live.
Why the distractors are wrong:
- A (image file): This is used to analyze a previously acquired forensic image, not to access a live system's protected files.
- C (server object settings): Not a valid FTK Imager evidence item type - this is a fabricated distractor with no relevance to the tool's workflow.
- D (profile access control list): Also not an FTK Imager evidence item type; ACLs are a Windows permissions concept, not an acquisition source.
Memory tip: Think LIVE = BOOTED - if the machine is live (running), you add the currently booted drive. The word "currently" is the giveaway that the system must be on and active, matching the "live machine" scenario in the question.
Topics
Community Discussion
No community discussion yet for this question.