Digital Forensics Flashcards

1
Q

CMOS

A

Where a computer stores system configuration and date and time information when the system is off.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

• Memory or Cache memory

A

contain the bootloader – Where the OS is loaded by the bootstrap. it’s a portion of your RAM that is directly attached to the central processing unit-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

• Master Boot Record (MBR

A

MBR is where the partitions information are saved; it’s created when a hard drive is partitioned. MRR is located on the first sector or sector 1 of a disk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

• Boot section

A

: Comprise partitions that describe the rest of the file system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

• bootstrap program

A

: Is used for loading the operating system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

• Partitions:

A

A logical drive on a disk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

• Partition table :

A

is in the MBR at sector 0 of the disk drive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Logical addresses

A

: point to relative cluster positions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Physical addresses :

A

Actual sector in which files are located

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

fat

A

The mechanism that keeps track of files stored on disk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Boot Record:

A

Contains information that the system uses to access the volume. It’s a relative address 0. The first 512 bytes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

• BIOS –

A

Computer configuration is saved in the BIOS. System BIOS or EFI contains programs that perform input and output at the hardware level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

• power-on-self-test (POST) –

A

Software embedded in the hardware that check if a hardware is missing .It is the first step of the boot sequence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Hives :

A

LOGICAL GROUP OF KEYS,, SUBKEYS, AND VALUES IN THE REGISTRY.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HKEY_CLASSES_ROOT

A

Provides file type and file extension information. URL protocol, and so forth. It’s linked to HKEY_LOCAL_MACHINE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

HKEY_CURRENT_USER

A

Store settings to the curently logged-on user. Linked to HKEY_USERS

17
Q

HKEY_LOCAL_MACHINE

A

Contains Information about installed hardware and software.

18
Q

HKEY_USERS

A

Stores information for the currently logged-on user. Contain inforation about all users who has account on the computer. only one key in this HKEY is linked to HKEY_CURRENT_USER

19
Q

HKEY_CURRENT_CONFIG

A

contains current hardware configuration settings. Liked to HKEY_LOCAL_MACHINE\SYSTEM

20
Q

HKEY_DYN_DATA

A

Udr only in Windows 9x/ME systems. Stores configuration settings

21
Q

Bitmaps

A

are used to represent image on the computer. They are defined as rectangular mesh of cells called pixels

22
Q

Resolution

A

Resolution is an attribute of a bitmap that is necessary when visually viewing or printing bitmaps because pixels by themselves have no explicit dimensions

23
Q

PST or PFF

A

is a file where Microsoft Outlook stores all of outlook items

24
Q

mkdir email_forensics

A

make directory email_ forensics

25
Q

cd email_forensics/

A

change directory email_forensics

26
Q

Lspst

A

list PST files

27
Q

Readpst

A

read all PST files

28
Q

mkdir crack

A

Make directory crack

29
Q

wget https:www

A

it’s to download file over a network

30
Q

ls

A

list segment/contents