Working with Windows and CLI systems Flashcards

(46 cards)

1
Q

Which filename refers to the device driver that allows the OS to communicate with SCSI or ATA drives that aren;t related to the BIOS?

A

NTBootdd.sys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which certificate provides a mechanism for recovering files encrypted with EFS if there is a problem with the user’s original private key?

A

Recovery Certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which filename refers to the physical address support program for accessing more than 4 GB of physical RAM?

A

Ntkmlpa.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Alternate data streams can obscure valuable evidentiary data, intentionally or by coincidence.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which filename refers to a 16-bit real-mode program that queries the system for device and configuration data, and then passes its findings to Ntldr?

A

NTDetect.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The first 5 bytes (characters) for all MFT records are FILE.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The file or folder’s MFT record provides cluster addresses where the file is stored on the drive’s partition. What are these cluster addresses called?

A

Data runs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which acronym refers to the file structure database that Microsoft originally designed for floppy disks?

A

FAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In the NTFS MFT, all files and folders are stored in separate records of how many bytes each?

A

1024

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Typically, a virtual machine consists of just one file.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

As data is added, the MFT can expand to take up 75% of the NTFS disk.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In Microsoft file structures, sectors are grouped to form clusters, which are storage allocation units of one or more sectors.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the name of the optional built-in encryption that Microsoft added to NTFS when Windows 2000 was introduced?

A

EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

One way to examine a partition’s physical level is to use a disk editor, such as WinHex, or Hex Workshop.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What term refers to the number of bits in one square inch of a disk platter?

A

Areal density

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is on an NTFS disk immediately after the Partition Boot Sector?

A

MFT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What enables the user to run another OS on an existing physical computer (known as the host computer) by emulating a computer’s hardware environment?

A

A virtual machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which acronym refers to the file system that was introduced when Microsoft created Windows NT and that remains the main file system in Windows 10?

A

NTFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

The type of file system an OS uses determines how data is stored on the disk.

20
Q

It’s possible to create a partition, add data to it, and then remove references to the partition so that it can be hidden in Windows.

21
Q

When Microsoft created Windows 95, into what were initialization (.ini) files consolidated?

22
Q

Drive slack includes RAM slack (found mainly in older Microsoft OSs) and file slack.

23
Q

From a network forensics standpoint, there are no potential issues related to using virtual machines.

24
Q

What specifies the Windows XP path installation and contains options for selecting the Windows version?

25
What term refers to a column of tracks on two or more disk platters?
Cylinder
26
In NTFS, files smaller than 512 bytes are stored in the MFT.
True
27
Which of the following Windows 8 files contains user-specific information?
Ntuser.dat
28
EFS can encrypt which of the following?
Files, folders, and volumes
29
MFT stands for Master File Table
True
30
File and directory names are some of the items stored in the FAT database
True
31
An image of a suspect drive can be loaded on a virtual machine
True
32
List two features NTFS has that FAT does not
Unicode characters and better security
33
What happens when you copy an encrypted file from an EFS-enabled NTFS disk to a non-EFS disk or folder?
The file is unencrypted automatically
34
A virtual cluster number represents the assigned clusters of files that are non resident in the MFT
True
35
Areal density refers to which of the following?
Number of bits per square inch of a disk platter
36
Zone bit recording is how disk manufacturers ensure that a platter's outer tracks store as much data as possible
False
37
How many sectors are typically in a cluster on a disk drive?
4 or more
38
In FAT32, a 123-KB file uses how many sectors?
246
39
CHS stands for cylinders, heads, and sectors
True
40
Device drivers contain instructions for the OS on how interface with hardware devices
True
41
What does the Ntuser.dat file contain?
MRU files list
42
In Windows 7 and later, how much data from RAM is loaded into RAM slack on a disk drive?
None of the above
43
Clusters in Windows always being numbering at what number?
2
44
What is the space on a drive called when a file is deleted?
Unallocated space
45
Virtual machines have which of the following limitations when running on a host computer?
Virtual machines are limited to host computer's peripheral configurations, such as mouse, keyboard, CD/DVD drives, and other devices
46
BIOS boot firmware was developed to provide better protection against malware than EFI does developed?
False