Digital Forensics 2 Flashcards

1
Q

Email Provider Extensions :

(Outlook) = ???
(Offline Outlook Storage) = ???
(Outlook Express) = ??? or ???
(Eudora) = ???
(common to several e-mail clients) = ???
A
(Outlook) .pst
(Offline Outlook Storage) .ost
(Outlook Express) .mbx or .dbx
(Eudora) .mbx
(common to several e-mail clients) .emi
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RFC 3864 describes message header field names. The header field used commonly with values “bulk,” “junk,” or “list”; and that indicate that automated “vacation” or “out of office” responses should not be returned for this mail refers to which of the following options?

A

precedence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

the core of the OS

A

Ntoskrnl.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A program that handles services on your system

A

Smss.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

program that logs you on

A

Winlogon.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The interface the user interacts with, such as the desktop, Windows Explorer, and so on …

A

Explorer.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The ForwardedEvents log is used to store events collected from remote computers. This has data in it only if event forwarding has been configured.

A

The ForwardEvents Log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Even if the suspect’s browsing history has been erased, it is still possible to retrieve it if he or she was using Internet Explorer. Index.dat is a file used by Microsoft Internet Explorer to store Web addresses, search queries, and recently opened files. So if a file is on a universal serial bus (USB) device but was opened on the suspect machine, index.dat would contain a record of that file.

A

index.dat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Windows has a number of files. A program that queries the computer for basic device/configuration data like time/date from CMOS, system bus types, disk drives, ports, and so on is __________.

A

ntdetect.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Dynamic memory for a program comes from the heap segment; a process may use a memory allocator such as malloc to request dynamic memory.

A

definition of a heap?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly