Digital Forensics: Four basic types of disk-based forensic data Flashcards

1
Q

Allocated Space

A

The portions of the disk that are marked as actively containing
data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Unallocated Space

A

The portions of the disk that does not contain active

data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Unallocated Space

A

There are parts that have never been allocated and

previously allocated parts that have been marked unallocated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Unallocated Space

A

When a file is deleted, the parts of the disk that held
the deleted file are marked as unallocated and made available
for use. (This is also why deleting a file does nothing, the data is still there until overwritten).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Slack Space

A

Data is stored in specific size chunks known as clusters (clusters = sectors or blocks).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Slack Space

A

A cluster is a minimum size that can be allocated by a file system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Slack Space

A

If a particular file, or the final portion of a file, does not require the use of the entire cluster then some extra space will exist within the cluster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Slack Space

A

This leftover space is known as slack space: it may contain old data or can be used intentionally by attackers to hide information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Bad Blocks/Clusters/Sectors

A

Hard disks end up with sectors that cannot be read due to some physical defect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Bad Blocks/Clusters/Sectors

A

The sectors marked as bad will be ignored by the operating system since no data could be read in those defective portions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Bad Blocks/Clusters/Sectors

A

Attackers can mark sectors or clusters as being bad in order to hide data within this portion of the disk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly