A30-327 · Question #24
What are three types of evidence that can be added to a case in FTK? (Choose three.)
The correct answer is A. local drive C. contents of a folder D. acquired image of a drive. In FTK, evidence is added as a source container - something that holds data to be processed. A local drive (A), contents of a folder (C), and an acquired image of a drive (D) all represent primary data sources that FTK can ingest and process directly: physical media, a…
Question
Options
- Alocal drive
- Bregistry MRU list
- Ccontents of a folder
- Dacquired image of a drive
- Ecompressed volume files (CVFs)
How the community answered
(48 responses)- A94% (45)
- B2% (1)
- E4% (2)
Explanation
In FTK, evidence is added as a source container - something that holds data to be processed. A local drive (A), contents of a folder (C), and an acquired image of a drive (D) all represent primary data sources that FTK can ingest and process directly: physical media, a directory on a filesystem, or a forensic image file (e.g., .E01, .dd).
B is wrong because a registry MRU list is an artifact discovered during analysis, not a source you add to a case - you find MRU entries after processing a drive or image, not before.
E is wrong because compressed volume files (CVFs, associated with legacy Microsoft DriveSpace/DoubleSpace) are a file type that may exist within evidence, not a standalone evidence source type FTK accepts at intake.
Memory tip: Think "where does the data live before analysis?" - a drive, a folder, or a disk image. If it's something you find during analysis (like an MRU list) or a legacy file format nested inside storage (like a CVF), it's not an evidence source you add to the case.
Topics
Community Discussion
No community discussion yet for this question.