Disk Imaging Flashcards

1
Q

In imaging vs copying, imaging captures…

A

slack space
unallocated space
deleted files
file metadata

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In imaging vs cloning, imaging is…

A

not bootable
compressed
checksummed
examinable with forensic tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of volumes that can be imaged

A

Physical volumes
Logical volumes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why image physically?

A

To get the full drive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why image logically?

A

Usually faster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you image if the disk is encrypted?

A

Logically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Forensic Triage

A

Collects the most useful files from a disk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Live imaging

A

Imaging while a machine is on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Boot imaging

A

Booting into a different machine to take the image.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Dead box imaging

A

Pulling a hard drive and imaging it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What tool lets you check for encryption?

A

EDD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When would you boot image?

A

Whenever you cannot remove the hard drive from the machine and the drive is not encrypted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly