CHFI Online Study Notes Flashcards
What are the essential Windows system files?
Ntoskrnl.exe
Which of the following is NOT a disk editor tool to help view file headers and important information about a file?
Win Edit
Hex Workshop
Disk Edit
WinHex
Win Edit
Which LBA contains the GPT header?
LBA 1
Which of the following items is used to describe the characteristics of the file system information present on a given CD-ROM?
POSIX attribute
Track header
Boot sector
Volume descriptor
Volume descriptor
Which of the following is NOT an advantage of SSDs over HDDs? Higher reliability Non-volatile memory Faster data access Less power usage
Non-volatile memory
Which field type refers to the volume descriptor as a supplementary?
Number 2
What is a hard disk’s first sector that specifies the location of an operating system for the system to load into the main storage?
Master Boot Record
Which field type refers to the volume descriptor as a set terminator?
Number 255
Which of the following should be work area considerations for forensic labs?
Examiner station has an area of about 50–63 square feet.
Which of the following is a computer-created source of potential evidence?
Swap File
Forensic readiness refers to:
An organization’s ability to make optimal use of digital evidence in a limited period and with minimal investigation costs.
Which of the following Windows operating systems powers on and starts up using only the traditional BIOS-MBR method?
Windows Vista
Which of the following is a consideration of HDDs but not SSDs?
RPM Speed
Which item describes the following UEFI boot process phase? (The phase of EFI consisting of interpreting the boot configuration data, selecting the Boot Policy for later implementation, working with the prior phase to check if the device drivers require signature verification, loading either MBR boot code into memory for Legacy BIOS Boot or the Bootloader program from the EFI partition for UEFI Boot, and providing an option for the user to choose EFI Shell or an UEFI application as the Boot Device from the Setup.)
BDS (Boot Device Selection) Phase
Which of the following is NOT a common computer file system? EXT2 NTFS EFX3 FAT32
EFX3
What is the role of an expert witness?
To educate the public and court
Which of the following Federal Rules of Evidence ensures that the truth may be ascertained and the proceedings justly determined?
Rule 102
Which of the following is one of the five UEFI boot process phases?
BSD Phase
RT Phase
PAI Phase
PIE Phase
RT Phase
Which of the following describes when the user restarts the system via the operating system?
Warm Booting
What do GPTs use instead of the addressing used in modern MBRs?
LBA
Which of the following is a 128-bit unique number, generated by the Windows OS for identifying a specific device, document, database entry, or user?
Globally Unique Identifier (GUID)
The UEFI assigns how many bytes for the Partition Entry Array?
16,384
Which of the following is a user-created source of potential evidence?
Address Book
Which of the following should be physical location and structural design considerations for forensics labs?
Lab exteriors should have no windows.