You are attempting to access data from the Protected Storage System Provider (PSSP) area of a registry. How do you accomplish this using PRTK?
To obtain protected files on a live machine with FTK Imager, which evidence item should be added?
You used FTK Imager to create several hash list files. You view the location where the files
were exported. What is the file extension type for these files?
Which pattern does the following regular expression recover?
(\d{4}[\- ]){3}\d{4}
You are converting one image file format to another using FTK Imager. Why are the hash
values of the original image and the resulting new image the same?
After creating a case, the Encrypted Files container lists EFS files. However, no decrypted
sub- items are present. All other necessary components for EFS decryption are present in the case. Which two files must be used to recover the EFS password for use in FTK? (Choose two.)
What are three types of evidence that can be added to a case in FTK? (Choose three.)
FTK uses Data Carving to find which three file types? (Choose three.)
FTK Imager allows a user to convert a Raw (dd) image into which two formats? (Choose two.)