Disk Wiping by any other name Flashcards

1
Q

What was the name of the Windows built-in disk wiping utility?

A

Cipher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How did Cipher work?

A

By filling a file with enough data to consume all available unallocated space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What was the problem with Cipher?

A

Could take up too much space so the OS would hang up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Windows doesn’t delete file data. What does it do when the delete file command is executed?

A

It marks the physical space that the files occupy as unallocated and available for reuse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the two problems caused when a disk sanitizer fails to overwrite old MFT entries?

A

Information can be inferred from these and some data may still remain if small enough

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Were the majority of disk wiping utilities effective at removing Alternate Data Streams?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Did the majority of disk wiping utilities effectively remove small datafiles that were present in the MFT?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why do the disk wiping utilities frequently miss small files that are stored in the MFT?

A

The area where these reside is not slack space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Do disk wiping utilities typically clean the registry hive?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the other category of utilities that are designed to be used prior to repurposing or recycling disk drives?

A

Disk sanitizers and disk purgers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Of the 7 disk wiping utilities analyzed, how many were shown to be effective?

A

One

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the term used to describe data that was unaffected by the disk wiping?

A

HKLM is an example

How well did you know this?
1
Not at all
2
3
4
5
Perfectly