Exam 1: Chapters 6-8 Flashcards
11 Questions
100 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which one of the following might leave behind 'footprints' if the computer is not shut down gracefully?

  • Autosave files
  • Undo files
  • Print spooler files
  • All of these (correct)
  • The appearance of a conflict of interest:

  • Could create a situation that casts doubt on the testimony of an analyst (correct)
  • Has no effect on the defense only on the prosecution
  • Has been ruled on by the 9th circuit court and has been shown to have no effect on the outcome of a case
  • Has no case law to support either good or bad results in court
  • After the conclusion of any criminal trial, if it becomes evident that an appeal is not possible, all contraband must be destroyed.

    True

    The NTFS file system stores information about the location of files, file names, and so forth in the ______.

    <p>Master file table</p> Signup and view all the answers

    A DoD approved disk wiping utility works by instructing the hard disk controller to apply a strong magnetic field to the disk surface, thereby electronically erasing the information from the disk.

    <p>False</p> Signup and view all the answers

    In the Windows operating systems, deleting a file from the Recycle Bin performs which of the following actions on the data stored on the surface of the medium?

    <p>Nothing happens to the data at this point. The allocation marker for the file is simply reset.</p> Signup and view all the answers

    Which of the following is an example of an individual characteristic of a 4th Generation iPod Classic?

    <p>It has 6,240 songs.</p> Signup and view all the answers

    Which of the following utilities was native to the Linux operating system and can be used to do string searches across multiple directories?

    <p>GREP</p> Signup and view all the answers

    What type of documents is an attorney trying to protect by filing a motion to have certain documents withheld from the discovery process?

    <p>Documents prepared by the legal team in anticipation of litigation.</p> Signup and view all the answers

    In the NTFS file system, how many versions of a file name are maintained?

    <p>Two. The file name given by the user along with an MS-DOS compatible version of that name.</p> Signup and view all the answers

    What is the name for the technique that allows an investigator to dig out certain types of files from unallocated space by identifying the header of that file type and copying all of the information between the head and a valid end of file marker?

    <p>Data carving</p> Signup and view all the answers

    Study Notes

    Temporary Files and Their Impact

    • Temporary files generated by operating systems may leave behind "footprints" if not shut down properly, including autosave, print spooler, and undo files.

    Conflict of Interest

    • The presence of a conflict of interest can undermine the perceived integrity of an analyst's testimony in legal cases.

    Contraband After Trial

    • All contraband must be destroyed once it is determined that no appeal is possible after a criminal trial conclusion.

    NTFS File System

    • The NTFS file system uses a Master File Table (MFT) to store crucial information about file locations and names.

    Disk Wiping Utilities

    • DoD approved disk wiping utilities do not erase information by applying a magnetic field to the disk; that method is incorrect.

    File Deletion in Windows

    • Deleting a file from the Recycle Bin only resets the allocation marker on the data, leaving it intact on the storage medium.

    Individual Characteristics in Evidence

    • Characteristics that uniquely identify an item include specific details like the number of songs (6,240) and a cracked screen cover of the iPod Classic.

    Linux Utility for String Searches

    • GREP is the native Linux utility used for performing string searches across multiple directories.

    Documents Protected as Work Product

    • Work product doctrine protects documents prepared by legal teams in anticipation of litigation from being disclosed during the discovery process.

    File Naming in NTFS

    • NTFS maintains two versions of a file name: the user-defined name and a compatible MS-DOS version.

    Data Recovery Techniques

    • Data carving is a technique used to recover specific types of files from unallocated space by identifying file headers and copying data to a valid end-of-file marker.

    Studying That Suits You

    Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

    Quiz Team

    Description

    Test your knowledge on key concepts from chapters 6 to 8 with our flashcards. This quiz covers various topics including operating systems and conflict of interest. Review essential definitions and scenarios to enhance your understanding.

    More Like This

    Operating Systems Chapter 6 Flashcards
    14 questions
    Operating Systems Chapter 4 Quiz
    28 questions
    Operating Systems and File Management
    51 questions
    IT Essentials 7.0 - Chapter 11 Flashcards
    39 questions
    Use Quizgecko on...
    Browser
    Browser