CHFI Online Study Notes Flashcards
What are the essential Windows system files?
Ntoskrnl.exe
Which of the following is NOT a disk editor tool to help view file headers and important information about a file?
Win Edit
Hex Workshop
Disk Edit
WinHex
Win Edit
Which LBA contains the GPT header?
LBA 1
Which of the following items is used to describe the characteristics of the file system information present on a given CD-ROM?
POSIX attribute
Track header
Boot sector
Volume descriptor
Volume descriptor
Which of the following is NOT an advantage of SSDs over HDDs? Higher reliability Non-volatile memory Faster data access Less power usage
Non-volatile memory
Which field type refers to the volume descriptor as a supplementary?
Number 2
What is a hard disk’s first sector that specifies the location of an operating system for the system to load into the main storage?
Master Boot Record
Which field type refers to the volume descriptor as a set terminator?
Number 255
Which of the following should be work area considerations for forensic labs?
Examiner station has an area of about 50–63 square feet.
Which of the following is a computer-created source of potential evidence?
Swap File
Forensic readiness refers to:
An organization’s ability to make optimal use of digital evidence in a limited period and with minimal investigation costs.
Which of the following Windows operating systems powers on and starts up using only the traditional BIOS-MBR method?
Windows Vista
Which of the following is a consideration of HDDs but not SSDs?
RPM Speed
Which item describes the following UEFI boot process phase? (The phase of EFI consisting of interpreting the boot configuration data, selecting the Boot Policy for later implementation, working with the prior phase to check if the device drivers require signature verification, loading either MBR boot code into memory for Legacy BIOS Boot or the Bootloader program from the EFI partition for UEFI Boot, and providing an option for the user to choose EFI Shell or an UEFI application as the Boot Device from the Setup.)
BDS (Boot Device Selection) Phase
Which of the following is NOT a common computer file system? EXT2 NTFS EFX3 FAT32
EFX3
What is the role of an expert witness?
To educate the public and court
Which of the following Federal Rules of Evidence ensures that the truth may be ascertained and the proceedings justly determined?
Rule 102
Which of the following is one of the five UEFI boot process phases?
BSD Phase
RT Phase
PAI Phase
PIE Phase
RT Phase
Which of the following describes when the user restarts the system via the operating system?
Warm Booting
What do GPTs use instead of the addressing used in modern MBRs?
LBA
Which of the following is a 128-bit unique number, generated by the Windows OS for identifying a specific device, document, database entry, or user?
Globally Unique Identifier (GUID)
The UEFI assigns how many bytes for the Partition Entry Array?
16,384
Which of the following is a user-created source of potential evidence?
Address Book
Which of the following should be physical location and structural design considerations for forensics labs?
Lab exteriors should have no windows.
Which item describes the following UEFI boot process phase? (The phase of EFI consisting of initializing the CPU, temporary memory, and boot firmware volume (BFV); locating and executing the chapters to initialize all the found hardware in the system; and creating a Hand-Off Block List with all found resources interface descriptors.)
PEI (Pre-EFI Initialization) Phase
Which file system for Linux transfers all tracks and boot images on a CD as normal files?
CDFS
On Macintosh computers, which architecture utilizes Open Firmware to initialize the hardware interfaces after the BootROM performs POST?
PowerPC
What replaces legacy BIOS firmware interfaces and uses a partition interfacing system to overcome the limitations of the MBR partitioning scheme?
UEFI (Unified Extensible Firmware Interface)
Which of the following is an advantage of the GPT disk layout?
GPT allows users to partition disks larger than 2 terabytes.
Which of the following is NOT part of the Computer Forensics Investigation Methodology?
Testify as an expert defendant.
Which of the following file systems are used for adding more descriptors to a CD-ROM’s file system sequence?
Joliet and UDF
Which of the following is TRUE of cybercrimes?
Investigators, with a warrant, have the authority to forcibly seize the computing devices.
Which commands help create MBR in Windows and DOS operating systems?
FDISK/MBR
Which of the following is a small piece of instruction in computer language, which the system loads into the BIOS and executes to initiate the system’s boot process?
Master Boot Code
Which logical drive holds the information regarding the data and files that are stored in the disk?
Extended Partition
Which cmdlet can investigators use in Windows PowerShell to analyze the GUID Partition Table to find the exact type of boot sector and display the partition object?
Get-PartitionTable
Which of the following basic partitioning tools displays details about GPT partition tables in Macintosh OS?
Disk Utility
How many tracks are typically contained on a platter of a 3.5″ HDD?
1,000
Under which of the following conditions will duplicate evidence NOT suffice?
When original evidence is in possession of the originator
Which field type in a volume descriptor refers to a boot record?
Number 0
Which of the following is NOT an objective of computer forensics?
Mitigate vulnerabilities to prevent further loss of intellectual property, finances, and reputation during an attack.
How many bytes is each partition entry in GPT?
128 Bytes