Podcast
Questions and Answers
What is the purpose of creating a custom content image in FTK Imager?
What is the purpose of creating a custom content image in FTK Imager?
- To extract registry hives and backup registry hives
- To create a disk-to-image copy of the entire hard drive
- To analyze the RECENT folder and subfolders
- To image a live system, a dead system, or an image file (correct)
What type of files can be found in the User's Home folder of 'APPDATA'?
What type of files can be found in the User's Home folder of 'APPDATA'?
- Registry hives and backup registry hives
- Cache, history, cookies files, and more (correct)
- Event Log files
- Prefetch files
What is the purpose of using a hardware write-blocker in the imaging process?
What is the purpose of using a hardware write-blocker in the imaging process?
- To connect the evidence disk to the forensic workstation
- To create a quick triage image
- To boot to Windows
- To prevent changes to the original evidence drive (correct)
What is the term for creating a copy of the entire hard drive at the logical partition and physical drive level?
What is the term for creating a copy of the entire hard drive at the logical partition and physical drive level?
What is the purpose of the RECENT folder and subfolders?
What is the purpose of the RECENT folder and subfolders?
What is the tool used to create a disk image in the imaging process?
What is the tool used to create a disk image in the imaging process?
What is the purpose of the 'APPDATA' folder?
What is the purpose of the 'APPDATA' folder?
What is the term for the process of creating a copy of the RAM?
What is the term for the process of creating a copy of the RAM?
What is the purpose of creating a triage image?
What is the purpose of creating a triage image?
What is RAID?
What is RAID?