Final Exam Flashcards

1
Q

List 4 File Systems

A

a. FAT32
b. NTFS
c. HFS
d. EXT4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

List 4 requirement of all file systems

A

a. Object Name
b. Starting cluster
c. Allocation
d. Fragmentation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a MBR and where is it found (assume a windows system) and what does it do?

A

Master Boot Record. It’s found at Sector 0. It contains partition table which consist of 4 sixteen Byte records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a sector?

A

A smallest physical storage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Plist

A

The preferred way to store property lists on OS X and and IOS. They are in the format XML.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a cluster or block?

A

A combination of one or more sectors allocated to store data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Value of Volume boot record:

A

The number of sector per clusters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Volume shadow copy:

A

Allows to recover disk or volume at some point. Hacker likely to turn off this for ransom.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Volatile data :

A

Data that is lost when a computer is turned off. Volatile storage is a form of temporary memory. It contains the most update activities of the user, it also help determine if an external drive had been used
Volatile data provides useful information during network intrusion investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Differentiate between a physical file and a logical file

A

Logical : The actual size of the file

Physical : The size of the cluster reserved for the file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the difference between a physical disk image and a logical disk image?

A

Logical disk is the volume

Physical Disk: Has the volume

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  1. What is file slack, why does a data persist there and how long it stay?
A

Unused space of a cluster. It persist there because not all sectors allocated hold the file. It will stay there until a new file larger than the original file is written on that cluster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  1. Define Allocated vs unallocated disk space?
A

Allocated is the space contained data. Unallocated is the free space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a bit stream image? Can I bit stream the acquisition of a logical drive?

A

Copy-by-copy, byte-by-byte of the hard drive without altering the original drive. Yes I can bit stream a logical drive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the difference between a “partition” and a “volume”?

A

When a partition is formatted, it’s becomes a volume.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is fragmentation and why should we care?

A

Involves splitting data into smaller fragment and distributing them across a larger number of machine. Fragmentation can hold slack file.

17
Q

What is hash collision:

A

When the content of data is altered, but its hash is still the same as the original.

18
Q

When imaging an iPhone,

A

we get a recent database which may have some emails. MAC is always changing. MAC is moving away from PList to SQLite data base.

19
Q

SQLite data base

A

SQLite data base use for SMS, address book in phones, internet history in phones and in computer, setting been stored

20
Q

What is Plist

A

The preferred way to store property lists on OS X and and IOS. They are in the format XML.

21
Q

What is a VBR and where is it found (assume a windows system) and what does it do?

A

Volume Boot Record. It’s found at the First sector of a volume. In windows, it’s found at sector 63 or 2048 for the first volume.

VBR contains the sector per cluster as well as volume serial number. It’s used to identify the file system of the volume.