Working with Windows and CLI systems Flashcards

1
Q

Which filename refers to the device driver that allows the OS to communicate with SCSI or ATA drives that aren;t related to the BIOS?

A

NTBootdd.sys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which certificate provides a mechanism for recovering files encrypted with EFS if there is a problem with the user’s original private key?

A

Recovery Certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which filename refers to the physical address support program for accessing more than 4 GB of physical RAM?

A

Ntkmlpa.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Alternate data streams can obscure valuable evidentiary data, intentionally or by coincidence.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which filename refers to a 16-bit real-mode program that queries the system for device and configuration data, and then passes its findings to Ntldr?

A

NTDetect.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The first 5 bytes (characters) for all MFT records are FILE.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The file or folder’s MFT record provides cluster addresses where the file is stored on the drive’s partition. What are these cluster addresses called?

A

Data runs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which acronym refers to the file structure database that Microsoft originally designed for floppy disks?

A

FAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In the NTFS MFT, all files and folders are stored in separate records of how many bytes each?

A

1024

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Typically, a virtual machine consists of just one file.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

As data is added, the MFT can expand to take up 75% of the NTFS disk.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In Microsoft file structures, sectors are grouped to form clusters, which are storage allocation units of one or more sectors.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the name of the optional built-in encryption that Microsoft added to NTFS when Windows 2000 was introduced?

A

EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

One way to examine a partition’s physical level is to use a disk editor, such as WinHex, or Hex Workshop.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What term refers to the number of bits in one square inch of a disk platter?

A

Areal density

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is on an NTFS disk immediately after the Partition Boot Sector?

A

MFT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What enables the user to run another OS on an existing physical computer (known as the host computer) by emulating a computer’s hardware environment?

A

A virtual machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which acronym refers to the file system that was introduced when Microsoft created Windows NT and that remains the main file system in Windows 10?

A

NTFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

The type of file system an OS uses determines how data is stored on the disk.

A

True

20
Q

It’s possible to create a partition, add data to it, and then remove references to the partition so that it can be hidden in Windows.

A

True

21
Q

When Microsoft created Windows 95, into what were initialization (.ini) files consolidated?

A

The registry

22
Q

Drive slack includes RAM slack (found mainly in older Microsoft OSs) and file slack.

A

True

23
Q

From a network forensics standpoint, there are no potential issues related to using virtual machines.

A

False

24
Q

What specifies the Windows XP path installation and contains options for selecting the Windows version?

A

Boot.ini

25
Q

What term refers to a column of tracks on two or more disk platters?

A

Cylinder

26
Q

In NTFS, files smaller than 512 bytes are stored in the MFT.

A

True

27
Q

Which of the following Windows 8 files contains user-specific information?

A

Ntuser.dat

28
Q

EFS can encrypt which of the following?

A

Files, folders, and volumes

29
Q

MFT stands for Master File Table

A

True

30
Q

File and directory names are some of the items stored in the FAT database

A

True

31
Q

An image of a suspect drive can be loaded on a virtual machine

A

True

32
Q

List two features NTFS has that FAT does not

A

Unicode characters and better security

33
Q

What happens when you copy an encrypted file from an EFS-enabled NTFS disk to a non-EFS disk or folder?

A

The file is unencrypted automatically

34
Q

A virtual cluster number represents the assigned clusters of files that are non resident in the MFT

A

True

35
Q

Areal density refers to which of the following?

A

Number of bits per square inch of a disk platter

36
Q

Zone bit recording is how disk manufacturers ensure that a platter’s outer tracks store as much data as possible

A

False

37
Q

How many sectors are typically in a cluster on a disk drive?

A

4 or more

38
Q

In FAT32, a 123-KB file uses how many sectors?

A

246

39
Q

CHS stands for cylinders, heads, and sectors

A

True

40
Q

Device drivers contain instructions for the OS on how interface with hardware devices

A

True

41
Q

What does the Ntuser.dat file contain?

A

MRU files list

42
Q

In Windows 7 and later, how much data from RAM is loaded into RAM slack on a disk drive?

A

None of the above

43
Q

Clusters in Windows always being numbering at what number?

A

2

44
Q

What is the space on a drive called when a file is deleted?

A

Unallocated space

45
Q

Virtual machines have which of the following limitations when running on a host computer?

A

Virtual machines are limited to host computer’s peripheral configurations, such as mouse, keyboard, CD/DVD drives, and other devices

46
Q

BIOS boot firmware was developed to provide better protection against malware than EFI does developed?

A

False