Digital Forensics Flashcards

1
Q

What are the components of a hard disk drive

A
  • Platter
  • Head
  • Head motor
  • Controller/cache
  • Platter Motor
  • Casing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the structure of the platter?

A
  • Tracks
  • Sectors
  • Cluster
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many sectors form a cluster?

A

Sectors are typically organised into groups of 4 and 4 sectors form a cluster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does one complete circuit around the drive form?

A

A track

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How is information stored on the platter?

S

A

In chunks which are sectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does the platter store information?

A

Platters store the information magnetically, magnetic dipoles pointing up and down representing 1’s and 0’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does a hard disk operate?

Head glides

A
  • Each rotating disk (platter) is made up of a thin layer of magnetically responsive material in which the data is stored (as binary).
  • Platters spin extremely fast 3,600-12,000 rpm.
  • Head glides on cushion of air cause by spin of platter (millionths of inch above).
  • Side to side movement of the head arm allows any position on the disk to be read/written.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When do files actually get deleted?

A
  • Deleted files are flagged as free space and aren’t deleted until it has been overwritten with another file and even then the overwritten file may not take up all the space so file fragments will be in the remaining cluster slacks.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How can you obtain information from a USB?

A
  • Make an exact bit copy of the USB.
  • This is done using a device called a physical write blocker.
  • This allows you to read the information off the USB stick but won’t allow you to change anything. - It’s a one-way data blocker. (reads the data but doesn’t change anything)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What should you not do with USB evidence?

A

You shouldn’t plug the USB into your PC as it could change the time or date stamp on a file which can invalidate the evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an exact bit-for-bit copy of a USB called?

A

Image file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly