Digital Forensics 2 Flashcards
Email Provider Extensions :
(Outlook) = ??? (Offline Outlook Storage) = ??? (Outlook Express) = ??? or ??? (Eudora) = ??? (common to several e-mail clients) = ???
(Outlook) .pst (Offline Outlook Storage) .ost (Outlook Express) .mbx or .dbx (Eudora) .mbx (common to several e-mail clients) .emi
RFC 3864 describes message header field names. The header field used commonly with values “bulk,” “junk,” or “list”; and that indicate that automated “vacation” or “out of office” responses should not be returned for this mail refers to which of the following options?
precedence
the core of the OS
Ntoskrnl.exe
A program that handles services on your system
Smss.exe
program that logs you on
Winlogon.exe
The interface the user interacts with, such as the desktop, Windows Explorer, and so on …
Explorer.exe
The ForwardedEvents log is used to store events collected from remote computers. This has data in it only if event forwarding has been configured.
The ForwardEvents Log
Even if the suspect’s browsing history has been erased, it is still possible to retrieve it if he or she was using Internet Explorer. Index.dat is a file used by Microsoft Internet Explorer to store Web addresses, search queries, and recently opened files. So if a file is on a universal serial bus (USB) device but was opened on the suspect machine, index.dat would contain a record of that file.
index.dat
Windows has a number of files. A program that queries the computer for basic device/configuration data like time/date from CMOS, system bus types, disk drives, ports, and so on is __________.
ntdetect.com
Dynamic memory for a program comes from the heap segment; a process may use a memory allocator such as malloc to request dynamic memory.
definition of a heap?