nerdexam
Access_Data

A30-327 · Question #2

To obtain protected files on a live machine with FTK Imager, which evidence item should be added?

The correct answer is B. currently booted drive. Option B is correct because FTK Imager can access protected or locked files on a running system by adding the currently booted drive as an evidence item - this lets the tool read files that the OS would normally lock or restrict, since the drive is being accessed at a lower…

Data Acquisition and Preservation

Question

To obtain protected files on a live machine with FTK Imager, which evidence item should be added?

Options

  • Aimage file
  • Bcurrently booted drive
  • Cserver object settings
  • Dprofile access control list

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    79% (22)
  • C
    11% (3)
  • D
    7% (2)

Explanation

Option B is correct because FTK Imager can access protected or locked files on a running system by adding the currently booted drive as an evidence item - this lets the tool read files that the OS would normally lock or restrict, since the drive is being accessed at a lower level while the system is live.

Why the distractors are wrong:

  • A (image file): This is used to analyze a previously acquired forensic image, not to access a live system's protected files.
  • C (server object settings): Not a valid FTK Imager evidence item type - this is a fabricated distractor with no relevance to the tool's workflow.
  • D (profile access control list): Also not an FTK Imager evidence item type; ACLs are a Windows permissions concept, not an acquisition source.

Memory tip: Think LIVE = BOOTED - if the machine is live (running), you add the currently booted drive. The word "currently" is the giveaway that the system must be on and active, matching the "live machine" scenario in the question.

Topics

#FTK Imager#Live acquisition#Evidence collection#Protected file access

Community Discussion

No community discussion yet for this question.

Full A30-327 Practice