nerdexam
Access_Data

A30-327 · Question #54

You currently store alternate hash libraries on a remote server. Where do you configure FTK to access these files rather than the default library, ADKFFLibrary.hdb?

A. Preferences is correct because FTK's Preferences menu is where you configure application-level settings, including the path to alternate KFF (Known File Filter) hash libraries. When you need FTK to look at a remote server instead of the default ADKFFLibrary.hdb, you specify…

Forensic Process and Best Practices

Question

You currently store alternate hash libraries on a remote server. Where do you configure FTK to access these files rather than the default library, ADKFFLibrary.hdb?

Options

  • APreferences
  • BUser Options
  • CAnalysis Tools
  • DImport KFF Hashes

Explanation

A. Preferences is correct because FTK's Preferences menu is where you configure application-level settings, including the path to alternate KFF (Known File Filter) hash libraries. When you need FTK to look at a remote server instead of the default ADKFFLibrary.hdb, you specify that custom library path under Preferences.

B. User Options is wrong because it handles user-specific display and interface behavior, not hash library paths. C. Analysis Tools is wrong because it manages processing and analysis plugins, not hash library configuration. D. Import KFF Hashes is a distractor that sounds plausible but is used to add hash sets into an existing library - it doesn't redirect FTK to point at a different library location on a remote server.

Memory tip: Think "P for Path" - Preferences is where you set the Path to your remote hash library. Anything that changes where FTK looks for a resource lives in Preferences, while Import is only for bringing data in.

Topics

#FTK Configuration#Hash Libraries/KFF#Remote File Access#Preferences Management

Community Discussion

No community discussion yet for this question.

Full A30-327 Practice