Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the AccessData Certification A30-327 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam A30-327 Premium Access

View all detail and faqs for the A30-327 exam


480 Students Passed

92% Average Score

95% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

You create two evidence images from the suspect's drive: suspect.E01 and suspect.001. You want to be able to verify that the image hash values are the same for suspect.E01 and

suspect.001 image files. Which file has the hash value for the Raw (dd) image?

Options:

A.

suspect.001.txt

B.

suspect.E01.txt

C.

suspect.001.csv

D.

suspect.E01.csv

Questions # 2:

In FTK, a user may alter the alert or ignore status of individual hash sets within the active

KFF. Which utility is used to accomplish this?

Options:

A.

KFF Alert Editor

B.

ADKFF Library Selector

C.

Hash Database File Selector

D.

Hash Database Recovery Engine

Questions # 3:

When previewing a physical drive on a local machine with FTK Imager, which statement is true?

Options:

A.

FTK Imager can block calls to interrupt 13h and prevent writes to suspect media.

B.

FTK Imager can operate from a USB drive, thus preventing writes to suspect media.

C.

FTK Imager can operate via a DOS boot disk, thus preventing writes to suspect media.

D.

FTK Imager should always be used in conjunction with a hardware write protect device to

prevent writes to suspect media.

Questions # 4:

When adding data to FTK, which statement about DriveFreeSpace is true?

Options:

A.

DriveFreeSpace is merged with deleted files.

B.

DriveFreeSpace is segmented into 10 megabyte items.

C.

DriveFreeSpace is truncated, based on the size of the case.dat file.

D.

DriveFreeSpace is classified with file slack items in the Overview tab.

Questions # 5:

You are converting one image file format to another using FTK Imager. Why are the hash

values of the original image and the resulting new image the same?

Options:

A.

because FTK Imager's progress bar tracks the conversion

B.

because FTK Imager verifies the amount of data converted

C.

because FTK Imager compares the elapsed time of conversion

D.

because FTK Imager hashes only the data during the conversion

Questions # 6:

FTK uses Data Carving to find which three file types? (Choose three.)

Options:

A.

JPEG files

B.

Yahoo! Chat Archives

C.

WPD (Word Perfect Documents)

D.

Enhanced Windows Meta Files (EMF)

E.

OLE Archive Files (Office Documents)

Questions # 7:

Click the Exhibit button.

Question # 7

What change do you make to the file filter shown in the exhibit in order to show only graphics with a logical size between 500 kilobytes and 10 megabytes?

Options:

A.

You change all file status items to a red circle.

B.

You change all file status items to a yellow triangle.

C.

You make no change. The filter is correct as shown.

D.

You change Graphics in the File Type column to a yellow triangle.

Questions # 8:

You currently store alternate hash libraries on a remote server. Where do you configure FTK to access these files rather than the default library, ADKFFLibrary.hdb?

Options:

A.

Preferences

B.

User Options

C.

Analysis Tools

D.

Import KFF Hashes

Questions # 9:

Which pattern does the following regular expression recover?

(\d{4}[\- ]){3}\d{4}

Options:

A.

000-000-0000

B.

ddd-4-3-dddd-4-3

C.

000-00000-000-ABC

D.

0000-0000-0000-0000

Questions # 10:

You are asked to process a case using FTK and to produce a report that only includes selected graphics. What allows you to display only flagged graphics?

Options:

A.

List by File Path

B.

List File Properties

C.

Graphic Thumbnails

D.

Supplementary Files

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.