Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

AccessData A30-327 AccessData Certified Examiner Exam Practice Test

Demo: 9 questions
Total 60 questions

AccessData Certified Examiner Questions and Answers

Question 1

You create two evidence images from the suspect's drive: suspect.E01 and suspect.001. You want to be able to verify that the image hash values are the same for suspect.E01 and

suspect.001 image files. Which file has the hash value for the Raw (dd) image?

Options:

A.

suspect.001.txt

B.

suspect.E01.txt

C.

suspect.001.csv

D.

suspect.E01.csv

Question 2

Which two Registry Viewer operations can be conducted from FTK? (Choose two.)

Options:

A.

list SAM file account names in FTK

B.

view all registry files from within FTK

C.

create subitems of individual keys for FTK

D.

export a registry report to the FTK case report

Question 3

While analyzing unallocated space, you locate what appears to be a 64-bit Windows date and

time. Which FTK Imager feature allows you display the information as a date and time?

Options:

A.

INFO2 Filter

B.

Base Converter

C.

Metadata Parser

D.

Hex Value Interpreter

Question 4

After creating a case, the Encrypted Files container lists EFS files. However, no decrypted

sub- items are present. All other necessary components for EFS decryption are present in the case. Which two files must be used to recover the EFS password for use in FTK? (Choose two.)

Options:

A.

SAM

B.

system

C.

SECURITY

D.

Master Key

E.

FEK Certificate

Question 5

Which three items are displayed in FTK Imager for an individual file in the Properties

window? (Choose three.)

Options:

A.

flags

B.

filename

C.

hash set

D.

timestamps

E.

item number

Question 6

Into which two categories can an imported hash set be assigned? (Choose two.)

Options:

A.

alert

B.

ignore

C.

contraband

D.

system files

Question 7

In which Overview tab container are HTML files classified?

Options:

A.

Archive container

B.

Java Code container

C.

Documents container

D.

Internet Files container

Question 8

You successfully export and create a file hash list while using FTK Imager. Which three

pieces of information are included in this file? (Choose three.)

Options:

A.

MD5

B.

SHA1

C.

filename

D.

record date

E.

date modified

Question 9

When using Registry Viewer to view a key with 20 values, what option can be used to display only 5 of the 20 values in a report?

Options:

A.

Report

B.

Special Reports

C.

Summary Report

D.

Add to Report With Children

Demo: 9 questions
Total 60 questions