click below
click below
Normal Size Small Size show me how
Forenscis MC Final 3
| Question | Answer |
|---|---|
| Raw data is a direct copy of a disk drive. An example of a Raw image is output from the UNIX/Linux __ command. | dd |
| ______________ of data involves sorting and searching through all investigation data. | Discrimination |
| The simplest method of duplicating a disk drive is using a tool that does a direct ____________ copy from the original disk to the target disk. | disk-to-disk |
| To complete a forensic disk analysis and examination, you need to create a ______. | report |
| In Windows, the ___ command shows you the owner of a file if you have multiple users on the system or network. | Dir |
| A forensics workstation consisting of a laptop computer with a built-in LCD monitor and almost as many bays and peripherals as a stationary workstation is also known as a ________ ___________. | portable workstation |
| ____ ___ is a simple drive-imaging station. | FIRE IDE |
| Many vendors have developed write-blocking devices that connect to a computer through FireWire, ___ 2.0,and SCSI controllers. | USB |
| The ____ publishes articles, provides tools, and creates procedures for testing and validating computer forensics software. | NIST |
| The NIST project that has as a goal to collect all known hash values for commercial software applications and OS files is ____. | NSRL |
| The primary hash algorithm used by the NSRL project is _____. | SHA-1 |