Digital Forensics Flashcards
Main file system used by Windows Vista/7/8/10
New Technology File System (NTFS)
File system natively supports (read and write) by all OS’s
File Allocation Table - 32 (FAT32)
RAID 0
Striped Array:
Provides rapid access and increased storage but lacks redundancy
Min. num of drives: 2
I.e. Disk0 = A1 A3 A5 A7
Disk1 = A2 A4 A6 A8
RAID 1
Mirrored Array:
Designed for data recovery but more expensive than RAID 0
Min. num of drives: 2
I.e. Disk0 = A1 A2 A3 A4
Disk1 = A1 A2 A3 A4
RAID 5
Places parity recovery data on each disk
Min. num of drives: 3
I.e. Disk0 = A1 B1 C1 Dp
Disk1 = A2 B2 Cp D1
Disk2 = A3 Bp C2 D2
Disk3 = Ap B3 C3 D3
RAID 6
Redundant parity on each disk
Min. num of drives: 4
I.e. Disk0 = A1 B1 C1 Dp Eq Disk1 = A2 B2 Cp Dq E1 Disk2 = A3 Bp Cq D1 E2 Disk3 = Ap Bq C2 D2 E3 Disk4 = Aq B3 C3 D3 Ep
RAID 10
Mirrored striping:
Aka RAID 1+0, combo of RAID 1/0
Min. num of drives: 4
I.e. RAID0= ( RAID1 = Disk0 = A1 A3 A5 A7 Disk1 = A1 A3 A5 A7
RAID1 =
Disk2 = A2 A4 A6 A8
Disk3 = A2 A4 A6 A8
)
NFTS Organization
NTFS Boot Sector ->
Master File Table ($MFT) ->
File System Data ->
Master File Table Copy ($MFTMirr)
of bytes in a sector?
512 bytes
Size of every MFT data record?
Two sectors or 1024 bytes
How many date and time stamps can you examine in on MFT entry? (Small/Med/Large)
Small: 4
Med: 8
Large: 12
4th amendment of the US Constitution?
Protects against unreasonable search and seizure
5th amendment of the US constitution?
Protects against self-incrimination
What is a sector?
The smallest physical unit in which data is stored on a spinning hard drive
File header and signature for JPEG?
Header: FF D8 (ÿøÿá)
Signature: “FILE”