Digital Forensics Flashcards

1
Q

Main file system used by Windows Vista/7/8/10

A

New Technology File System (NTFS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

File system natively supports (read and write) by all OS’s

A

File Allocation Table - 32 (FAT32)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

RAID 0

A

Striped Array:
Provides rapid access and increased storage but lacks redundancy
Min. num of drives: 2

I.e. Disk0 = A1 A3 A5 A7
Disk1 = A2 A4 A6 A8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

RAID 1

A

Mirrored Array:
Designed for data recovery but more expensive than RAID 0
Min. num of drives: 2

I.e. Disk0 = A1 A2 A3 A4
Disk1 = A1 A2 A3 A4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

RAID 5

A

Places parity recovery data on each disk
Min. num of drives: 3

I.e. Disk0 = A1 B1 C1 Dp
Disk1 = A2 B2 Cp D1
Disk2 = A3 Bp C2 D2
Disk3 = Ap B3 C3 D3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

RAID 6

A

Redundant parity on each disk
Min. num of drives: 4

I.e. Disk0 = A1 B1 C1 Dp Eq
Disk1 = A2 B2 Cp Dq E1
Disk2 = A3 Bp Cq D1 E2
Disk3 = Ap Bq C2 D2 E3
Disk4 = Aq B3 C3 D3 Ep
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

RAID 10

A

Mirrored striping:
Aka RAID 1+0, combo of RAID 1/0
Min. num of drives: 4

I.e. 
RAID0= (
RAID1 =
Disk0 = A1 A3 A5 A7
Disk1 = A1 A3 A5 A7

RAID1 =
Disk2 = A2 A4 A6 A8
Disk3 = A2 A4 A6 A8
)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

NFTS Organization

A

NTFS Boot Sector ->
Master File Table ($MFT) ->
File System Data ->
Master File Table Copy ($MFTMirr)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

of bytes in a sector?

A

512 bytes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Size of every MFT data record?

A

Two sectors or 1024 bytes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How many date and time stamps can you examine in on MFT entry? (Small/Med/Large)

A

Small: 4
Med: 8
Large: 12

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

4th amendment of the US Constitution?

A

Protects against unreasonable search and seizure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

5th amendment of the US constitution?

A

Protects against self-incrimination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a sector?

A

The smallest physical unit in which data is stored on a spinning hard drive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

File header and signature for JPEG?

A

Header: FF D8 (ÿøÿá)
Signature: “FILE”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a cluster?

A

A group of sectors, commonly 8 sectors per cluster

17
Q

Advantages and disadvantages of a hard shutdown during digital evidence seizure

A

Advantages:
Simple, Effective, no software traps, no passwords needed
Disadvantages:
File system corruption, volatile data is lost, encryption

18
Q

Advantages and disadvantages of using RAW data acquisition format

A

Advantages:
Fast data transfers, Flat format, can split images into smaller segmented files, computer forensics tools can read raw format
Disadvantages:
No compression

19
Q

Features offered by proprietary formats?

A

Option to compress or not compress image files, can integrate metadata into the image file, offers encryption/password protection options

20
Q

Two implementations methods used by hardware write-blockers

A

Write Failure, write success

21
Q

Benefits of hardware and software write protection?

A

Hardware: Independent of OS, portable, scalable
Software: Easy to install, easy to implement

22
Q

File deletion process for FAT32?

A
  1. The first character of the file name is changed to 0xE5

2. The clusters assigned to the file are marked as I allocated (0x00000000)

23
Q

File deletion process for NTFS?

A
  1. The index for the entry is removed after searched for, and entries in the node are moved and overwrite the original entry
  2. Flag within the files MFT entry is changed from 0x01 to 0x00
24
Q

Four possible entries used by FAT32 to represent a cluster’s status?

A
  1. Unallocated (0x0000 0000)
  2. Next Cluster in Run
  3. Bad Cluster (0x0FFF FFF7)
  4. Last Cluster in File (0x0FFF FFF8)
25
Q

Three possible attributes within an MFT Entry

A
  1. $STANDARD_INFORMATION (0x10)
  2. $FILE_NAME (0x30)
  3. $DATA (0x80)
27
Q

What are the four date and time stamps used in NTFS?

A

Access: last date and time the file was open
Modified: last date and time when the file’s data was changed
Entry: last date and time when the file’s attributes (MFT entry) were changed
Creation (Birth): Date and time when the file was created on the volume

28
Q

How to convert 16-bit FAT32 hex value to date? (Ex. 0x4393)

A
  1. Convert to binary
  2. Year is first 7 bits added to 1980, month is middle 4 bits, day is last 5 bits

010001 1100 10011 = 12/19/2013

29
Q

Difference between resident and non-resident data?

A

Resident data is contained within the MFT entry

30
Q

Four types of deleted data?

A
  1. Recycle Bin
  2. Deleted file/folder
  3. Data Carving
  4. File Slack
31
Q

Why are carved files difficult to use as evidence?

A

Their metadata is not recoverable

32
Q

Forensic implications of SSD wear-leveling technologies?

A

Wear-leveling destroys metadata used in forensics and data-recovery