You are using FTK to process e-mail files. In which two areas can E-mail attachments be located? (Choose two.)
Correct Answer:
AB
Which data in the Registry can the Registry Viewer translate for the user? (Choose three.)
Correct Answer:
BCE
A. E01 files
Correct Answer:
ABC
You create two evidence images from the suspect's drive: suspect.E01 and suspect.001. You want to be able to verify that the image hash values are the same for suspect.E01 and
suspect.001 image files. Which file has the hash value for the Raw (dd) image?
Correct Answer:
A
In FTK, which tab provides specific information on the evidence items, file items, file status and file category?
Correct Answer:
C