Exam 5: Working With Windows and Cli Systems
Exam 1: Understanding the Digital Forensics Profession and Investigations50 Questions
Exam 2: The Investigators Office and Laboratory50 Questions
Exam 3: Data Acquisition50 Questions
Exam 4: Processing Crime and Incident Scenes50 Questions
Exam 5: Working With Windows and Cli Systems50 Questions
Exam 6: Current Computer Forensics Tools50 Questions
Exam 7: Macintosh and Linux Boot Processes and File Systems48 Questions
Exam 8: Recovering Graphics Files49 Questions
Exam 9: Computer Forensics Analysis and Validation50 Questions
Exam 10: Virtual Machine and Cloud Forensics50 Questions
Exam 11: Live Acquisitions and Network Forensics50 Questions
Exam 12: Email Investigations50 Questions
Exam 13: Cell Phone and Mobile Device Forensics49 Questions
Exam 14: Report Writing for High Tech Investigations50 Questions
Exam 15: Expert Testimony in High Tech Investigations50 Questions
Exam 16: Ethics for the Investigator and Expert Witness50 Questions
Select questions type
The _______________ executable is the Windows Boot Manager program, which controls boot flow and allows booting multiple OSs.?
(Short Answer)
4.7/5
(34)
Match each term with the correct definition below:
-A public?/ private key encryption first used in Windows 2000 on NTFS-formatted disks. The file encrypted with a symmetric key, and then a public?/ private key is used to encrypt the symmetric key.?
(Multiple Choice)
4.9/5
(41)
The _________ branches in HKEY_LOCAL_MACHINE\Software consist of SAM, Security, Components, and System.
(Multiple Choice)
4.8/5
(41)
Explain the difference between logical addresses and physical addresses in Microsoft file structures.
(Essay)
4.9/5
(34)
_____________ is composed of the unused space in a cluster between the end of an active file's content and the end of the cluster.
(Short Answer)
4.8/5
(32)
Match each term with the correct definition below:
-A new file system developed for Windows Server 2012. It allows increased stability for disk storage and improved features for data recovery and error checking.?
(Multiple Choice)
5.0/5
(32)
Most manufacturers use what technique in order to deal with the fact that a platter's inner tracks have a smaller circumference than the outer tracks?
(Multiple Choice)
4.8/5
(35)
Why are alternate data streams of particular interest when examining NTFS disks?
(Essay)
4.9/5
(34)
Match each term with the correct definition below:
-?A 16-bit program that identifies hardware components during startup snd sends the information to Ntldr.
(Multiple Choice)
4.8/5
(36)
Which of the following is not a valid configuration of Unicode?
(Multiple Choice)
4.9/5
(37)
Match each term with the correct definition below:
-?A file that specifies the Windows path installation and a variety of other startup options.
(Multiple Choice)
4.8/5
(48)
Match each term with the correct definition below:
-?The original Microsoft file structure database. It's written to the outermost track of a disk and contains information about each file stored on the drive. PCs use this to organize files on a disk so that the OS can find the files it needs.
(Multiple Choice)
4.8/5
(33)
A Master Boot Record (MBR) partition table marks the first partition starting at what offset?
(Multiple Choice)
4.8/5
(39)
What registry file contains installed programs' settings and associated usernames and passwords?
(Multiple Choice)
4.9/5
(31)
Match each term with the correct definition below:
-?A device driver that allows the OS to communicate with SCSI or ATA drives that aren't related to the BIOS.
(Multiple Choice)
4.8/5
(39)
What term is used to describe a disk's logical structure of platters, tracks, and sectors?
(Multiple Choice)
4.8/5
(41)
What metadata record in the MFT keeps track of previous transactions to assist in recovery after a system failure in an NTFS volume?
(Multiple Choice)
4.8/5
(32)
Match each term with the correct definition below:
-?The file system that Microsoft created to replace FAT. It uses security features, allows smaller cluster sizes, and uses Unicode, which makes it a more versatile system.
(Multiple Choice)
5.0/5
(31)
Addresses that allow the MFT to link to nonresident files are known as _______________.
(Multiple Choice)
4.9/5
(39)
Showing 21 - 40 of 50
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)