Cloud Forensics Flashcards

1
Q

Cloud Service Models

A

IaaS
PaaS
SaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IaaS

A

This cloud computing service enables subscribers to use fundamental IT resources such as computing power, virtualization, data storage, network, and so on, on demand. As cloud service providers are responsible for managing the underlying cloud-computing infrastructure, subscribers can avoid costs of human capital, hardware, and others (e.g., Amazon EC2, Go grid, Sungrid, Windows SkyDrive).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PaaS

A

This service offers the platform for the development of applications and services. Subscribers need not buy and manage the software and infrastructure underneath it but have authority over deployed applications and perhaps application hosting environment configurations. Advantages of writing applications in the PaaS environment includes dynamic scalability, automated backups, and other platform services, without the need to explicitly code for i

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SaaS

A

This cloud computing service offers application software to subscribers’ on-demand, over the Internet. The provider charges for it on a pay-per-use basis, by subscription, by advertising, or by sharing among multiple use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Cloud Deployment Models

A

Public
Private
Hybrid
Community

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Cloud as a Subject

A

a crime in which the attackers try to compromise the security of a cloud environment to steal data or inject a malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Cloud as a Object

A

when the attacker uses the cloud to commit a crime targeted towards the CSP. In this case, the main aim of the attacker is to impact cloud service provider than cloud environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Cloud as a Tool

A

when the attacker uses one compromised cloud account to attack other accounts. In such cases, both the source and target cloud can store the evidence data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Dropbox

A

Dropbox comes with a feature called extended version history (EVH), which saves all the deleted and previous versions of the files by default. Dropbox offers this service in two versions, the free and the Dropbox Pro variant. The main difference is that the free version will store the previous versions of deleted files for 30 days, while the pro version can access any version at any given time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where is Dropbox client installed at on Win 10?

A

C:\Program Files (x86)\Dropbox

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Dropbox default folder for syncing is saved?

A

C:\Users\Dropbox

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Dropbox Registry Keys

A
  1. HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
  2. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIco nOverlayIdentifiers\DropboxExt(n)
  3. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox
  4. HKLM\SOFTWARE\Classes\DropboxUpdate.ProcessLauncher
  5. HKLM\SOFTWARE\Dropbox\InstallPath
  6. HKLM\SOFTWARE\Dropbox\Client\Version
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Where is the Dropbox config.db stored?

A

Path - C:\Users\AppData\Local\Dropbox\instance(n)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the Dropbox config.db?

A

What is it for? - Contains some information about local Dropbox installation and account. Lists the email IDs linked with the account, current version/build for the local application, the host_id, and local path information “config.dbx” is an encrypted variant of “config.db”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Where is the Dropbox filecache.db located?

A

C:\Users\AppData\Local\Dropbox\instance(n)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the Dropbox filecache.db?

A

It consists of several columns of which, “file_journal” is important as it contains a list of all directories and files inside “Dropbox”. It appears as if they are existing files, not deleted ones.

17
Q

Where is the Dropbox sigstore.db located?

A

Path - C:\Users\AppData\Local\Dropbox\instance(n)

18
Q

What is the Dropbox sigstore.db?

A

Records SHA-256 hash and each file’s size information

19
Q

Where is the Dropbox host.db?

A

C:\Users\AppData\Local\Dropbox

20
Q

What is the Dropbox host.db?

A

plain text file containing hash value(s) of usernames

21
Q

Where is the Dropbox unlink.db?

A

Path - C:\Users\AppData\Local\Dropbox

22
Q

What is the Dropbox unlink.db?

A

binary/database file

23
Q

Where is the Dropbox .dropbox.cache

A

C:\Users\Dropbox

24
Q

What is the Dropbox .dropbox.cache?

A

It is a hidden directory located at the root Dropbox folder that is used as a staging area for downloading and uploading files

25
Q

Where is Google Drive client install located?

A

C:\Program Files (x86)\Google\Drive

26
Q

Where is the Google Drive Syncing folder?

A

C:\Users\Google Drive

27
Q

Google Drive Registry Keys

A

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders HKCU\SOFTWARE\Google\Drive HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\GoogleDriveSync HKCU\SOFTWARE\Classes

28
Q

Sync_config.db is?.

A

Sync_config.db is a database file for the Google Drive Client that contains several records including the Google Drive version, the local sync root path, and the user’s email address.