lab 25 Flashcards

1
Q

How many formattable partitions are displayed by fdisk for this drive image?

1
3
5
6

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are possible explanations of the unaccounted for sectors from the extended partition? (Select two)

Unused space not allocated to a logical drive
Bad sectors on the original storage device
A hidden logical drive
The image is not in raw format

A

Unused space not allocated to a logical drive
A hidden logical drive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the names of the recovered files that are in sub-directories?

frag1.dat
frag3.dat
mult2.dat
sing1.dat

A

frag3.dat
mult2.dat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which recovered image file includes cats?

haxor2.jpg
paul.jpg
pumpkin.jpg
shark.jpg

A

pumpkin.jpg

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the maximum number of primary partitions that can be defined on an MBR drive if logical drives are in use?

1
2
3
4

A

3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following are tools from The Sleuth Kit (TSK)? (select all that apply)

tsk_recover
fsstat
fls
istat
mmls

A

tsk_recover
fsstat
fls
istat
mmls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the forensic process of recovering access to files that are otherwise inaccessible due to corruption, partial data loss (especially headers), deletion, or partition structure damage?

Data exfiltration
File carving
Acquisition
Evidence seizure

A

File carving

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an IoC that reveals the presence of a hidden partition?

Unused space in an extended partition
Corrupted MBR
Use of a GPT header
Only having 4 primary partitions

A

Unused space in an extended partition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a file system metadata structure that is used to store and organize file object information, such as file size, owner user, group IDs, permissions, and timestamps?

partition
sector
inode
MBR

A

inode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly