16-3 Flashcards

1
Q

the ___________ command lists any activie sessions connected to the computer you run it on

A

net sessions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

this is a command useful for finding live attacks ongoing

A

openfiles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

___ is a command you can use with a forensic copy of a machine. it compares 2 files and shows the difference.

A

fc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

used to detect ongoing attacks

A

netstat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

This is an incredible repository of potential valuable forensics information, the heart of windows.

A

windows registry

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

the registry key is __________ lists USB devices that have been connected to the machine

A

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Enum\USBSTOR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

this allows investigators to mathc the serial number ti a given drive letter

A

System\MountedDevices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

software packages used to gather infor from a sim card

A
CEllebrite
MOBILedit Forensics Express
BlackBag Technologies
magnet forensics
oxygen forensics
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

information to retrieve from a cell ohone

A
photo
video
texts or sms
call time, received calls, call durations
contact name and numbers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

the copying the active file system fromone device to another

A

logical imaging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

___________ are often the first tyoe fo examination forensics analysts will run because they are easy to execute

A

logical thechniques

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

the practice of removing a memory chip, or any chip from a circuit board and reading it

A

chip off technique

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Mobile devices that are implementing the BGA style memory incorporate __________ for test and debugging

A

JTAP Joint Test Action Group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

comonly called 2G technology. developed by european telecommunications standards institute. developed for digital voice

A

GSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

considered halfway between 2G and 3G

A

EDGE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

3G technology

A

UMTS

17
Q

4G technology. bbroadband internet, multimedia, and voice

A

LTE