Exam 18: Digital Evidence on Unix Systems

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

On UNIX systems, e-mails and all attachments are stored as plaintext in "/var/spool/mail," or "/var/mail," or in a directory under the user's account.

(True/False)
4.7/5
(38)

Why is it important to determine the level of network connectivity on a UNIX system as soon as possible?

(Multiple Choice)
4.8/5
(46)

The "istat" command, found in The Coroner's Toolkit, can be used to examine specific inode bitmaps.

(True/False)
4.8/5
(31)

FireFox 3 stores potentially notable information in:

(Multiple Choice)
4.7/5
(34)

When examining a UNIX system, searching for network traces is not usually necessary.

(True/False)
4.8/5
(34)

Deleting a file has the effect of preserving its inode until it is reused because:

(Multiple Choice)
4.8/5
(30)

The mainstay of acquiring digital evidence using UNIX is the "icopy" command.

(True/False)
4.8/5
(39)

The file system mount table shows local and remote file systems that are automatically mounted when the system is booted. This information is stored in:

(Multiple Choice)
4.9/5
(38)

UNIX log files (or those of any operating system, for that matter) can provide a great deal of useful information to the examiner.

(True/False)
4.9/5
(39)

When a target system is connected to other systems in remote locations, it is expedient for the digital investigator to access these systems via remote access.

(True/False)
4.9/5
(37)
Showing 21 - 30 of 30
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)