Windows Forensics Analysis: Acquisition and Memory Acquisition

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson
Download our mobile app to listen on the go
Get App

Questions and Answers

What is the purpose of creating a custom content image in FTK Imager?

  • To extract registry hives and backup registry hives
  • To create a disk-to-image copy of the entire hard drive
  • To analyze the RECENT folder and subfolders
  • To image a live system, a dead system, or an image file (correct)

What type of files can be found in the User's Home folder of 'APPDATA'?

  • Registry hives and backup registry hives
  • Cache, history, cookies files, and more (correct)
  • Event Log files
  • Prefetch files

What is the purpose of using a hardware write-blocker in the imaging process?

  • To connect the evidence disk to the forensic workstation
  • To create a quick triage image
  • To boot to Windows
  • To prevent changes to the original evidence drive (correct)

What is the term for creating a copy of the entire hard drive at the logical partition and physical drive level?

<p>Disk-to-image copy (D)</p> Signup and view all the answers

What is the purpose of the RECENT folder and subfolders?

<p>Not mentioned in the text (A)</p> Signup and view all the answers

What is the tool used to create a disk image in the imaging process?

<p>FTK Imager Lite (B)</p> Signup and view all the answers

What is the purpose of the 'APPDATA' folder?

<p>To store cache, history, cookies files, and more (A)</p> Signup and view all the answers

What is the term for the process of creating a copy of the RAM?

<p>Image Ram (D)</p> Signup and view all the answers

What is the purpose of creating a triage image?

<p>To perform a quick analysis of the evidence (B)</p> Signup and view all the answers

What is RAID?

<p>Not specified in the text (A)</p> Signup and view all the answers

Flashcards are hidden until you start studying

More Like This

Windows Swap File Quiz
88 questions
Disk and File System Forensics Analysis
49 questions
Use Quizgecko on...
Browser
Browser