Final 2 Flashcards

1
Q

APFS

A

A new file system for MAC that offers more option when turning a partition into a volume

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is alternative data stream:

A

ADS is the ability to fork file data into existing files without affecting their functionality, size, or display to traditional file browsing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

With FAT

A

To find names /dates, we look for directories entries. Allocation table is the FAT table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

With NTFS,

A

To find names and dates, we look for the Master Table file Records. Allocation table is $Bitmap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

With HFS,

A

we look for the CNID catalog the CNID does not get reused. Allocation table is catalog/allocation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where is a partition table?

A

A partition table is found on a MBR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

File System Tunneling:

A

deleting a file and immediately recreating a file with the same name in the same directory. The new file will inherit its creation date from the original file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Hacker methodology :

A

a- Reconnaissance: obtaining info on the target
b- Attack : Applying technique against target
c- Entrenchment : continue hidden the attack
d- Abuse: Conducting further activities on target.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

File carving:

A

Data carving is the process of extracting a collection of data from a larger data set. Data carving is done on a disk when the unallocated file system space is analyzed to extract files because data cannot be identified due to missing of allocation info.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Page file:

A

Are reserved portion of a hard drive disk that is used as an extension of RAM for data..

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Internal metadata:

A

Metadata that is stored internally to the file. They find on EXIF file (photographs, and media file), on pdf file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

File system metadata.

A

Information about file stored by the filesystem. It contains the create, modified, access, record update. They constitute file system metadata.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

OST File:

A

Offline stored file – Makes possible to work offline, and synchronize changes with the extend server once online.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

PST file :

A

Outlook data file used for most mail accounts. Used by POP3, IMAP and web based mail accounts. It’s a personal folder that store messages and other items on the computer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Gmail takeout

A

Allows google user to export their data to a downloadable zip. would do a dump of the user Gmail account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is data obfuscation:

A

Form of data masking that helps in concealing data. Example: Stenography, changing data extension, compressing data, write data into file or volume slack, create a small partition on a disk, populating it, then delete it., blurring data, shuffling data.

17
Q

Virus

A

Malicious software that self-replicate

18
Q

.

Alternate data stream in window where to found it:

A

It’s a Zone identifier which is created when a file is downloaded on the internet. It helps window to determine if a downloaded data on the internet is from a trusted zone.

19
Q

Hard link:

A

A label or names associated to a file i.e. Created multiple names that refer to a single file.

20
Q

Registry hive:

A

logical group of keys, sub keys, and values in the registry that has a set of supporting files containing backups of its data. All keys that are considered hives begin with “HKEYUser profiles hives are located in HkeyUSERS

21
Q

ADS in Mac

A

Data Force and Resource force :

22
Q

Forensics Soundness:

A

Any forensics method or technique of evidence collection that is verifiable and repeatable.

23
Q

What are link files:

A

are windows shortcut files that link to an application or file commonly found on a user’s desktop. Each link file has its own Created, Modified and Accessed dates and within each link file there are Created, Modified and Accessed dates which belong to the target file.

24
Q

Backup volume boot record (where it’s is found )

A
  • In NTFS, It’s the sector at the very end of the volume

- For FAT 32, it’s 6 sectors beyond the primary volume.