FTK Exam 1 ALL SOLUTION LATEST 2023 AID GRADE A+
Preview Look through evidence Triage Determine what evidence is pertinent to the case Imaging Creating a bit for bit copy Write blocker To ensure the integrity of the evidence by preventing writes or changes from occurring Forensic image, jury style Making a xerox copy of the digital evidence FTK can create these file formats Raw dd. SMART. EnCase. Advanced Forensics Format. AccessData Custom Content Logical Image. CD / DVD Imaging. Raw dd .001 SMART .S01 Encase .E01 Advanced Forensics Format .aff AccessData Custom Content Logical Image .AD1 CD / DVD Imaging .ISO / .cue Purpose of hashing Hashing is used to ensure that a file is not changed during processing and analysis of evidence. Types of hashing MD5. SHA1. SHA2. Bit output of MD5 128 Bit output of SHA1 160 Bit output of SHA2 256 Active Data is the information that you and I can see. Data files, programs, and files used by the operating system. This is the easiest type of data to obtain. Latent Data CONTINUED....
Written for
- Institution
- FTK E -1
- Course
- FTK E -1
Document information
- Uploaded on
- March 26, 2023
- Number of pages
- 6
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
- ftk exam 1
-
preview look through evidence triage determine what evidence is pertinent to the case imaging creating a bit for bit copy write blocker to ensure the integrity of the evidence by preventing