WGU D431 UPDATED STUDY EXAM GUIDE QUESTIONS
AND ANSWERS SURE A+
✔✔EnCase - ✔✔- from Guidance Software.
- is a very widely used forensic toolkit. allows examiner to connect an Ethernet cable or
null modem cable to a suspect machine and to view the data on that machine.
- prevents the examiner from making any accidental changes to the suspect machine.
- the evidence file is an exact copy of the hard drive.
- calculates an MD5 hash when the drive is acquired. This hash is used to check for
changes, alterations, or errors
- checks for steganography.
✔✔Forensic Toolkit - ✔✔- from AccessData.
- is particularly useful at cracking passwords.
- provides tools to search and analyze the Windows Registry.
- checks for steganography.
✔✔Steganography Tools - ✔✔QuickStego: very easy to use, but very limited.
Invisible Secrets: much more robust, with both a free and a commercial version.
MP3Stego: hides a payload in MP3 files.
Stealth Files 4: works with sound files, video files, and image files.
StegVideo: hides data in a video sequence.
Deep Sound: hides data in sound files.
✔✔Security Accounts Manager (SAM) - ✔✔file in the Windows System directory where
Windows stores hashes of passwords
✔✔Ophcrack - ✔✔Popular hacking tool that depends on rainbow tables. Is usually very
successful at cracking Windows local machine passwords.
✔✔Forensically important Windows directories - ✔✔C:\Windows documents and
settings
C:\Users
C:\Program File
C:\Program Files (x86)
, C:\Users\username\DocumentsRegistry
✔✔Registry hive & supporting files - ✔✔*HKEY_LOCAL_MACHINE\SAM: Sam,
Sam.log, Sam.sav*
HKEY_LOCAL_MACHINE\Security: Security, Security.log, Security.sav
HKEY_LOCAL_MACHINE\Software: Software, Software.log, Software.sav
HKEY_LOCAL_MACHINE\System: System, System.alt, System.log, System.sav
HKEY_CURRENT_CONFIG: System, System.alt, System.log, System.sav, Ntuser.dat,
Ntuser.dat.log
HKEY_USERS\DEFAULT: Default, Default.log, Default.sav
✔✔BASH shell - ✔✔The command prompt in Mac OS, can execute Linux commands.
✔✔Forensically important Mac OS logs, folders, and files - ✔✔/var/log
/var/spool/cups
/private/var/audit
/private/var/VM
/Library/Receipts
/Library/Mobile Documents
*/Users/<user>/.bash_history: BASH shell commands*
var/vm
/Users/
/Users/<user>/Library/Preferences
/Volumes
/Users
/Applications
/Network
*/etc: config files*
/Library/Preferences/SystemConfiguration/dom.apple.preferences.plist
✔✔Forensically important Android directories - ✔✔acct
cache
data
mnt
✔✔Forensic tools for mobile devices - ✔✔Forensic Toolkit and EnCase can both image
a phone
Oxygen Forensics
Cellebrite
MobileEdit
Data Doctor
Device Seizure
Forensic SIM Cloner
✔✔Data Doctor - ✔✔Recovers all Inbox and Outbox data and all contacts data, and has
an easy-to-use interface.
AND ANSWERS SURE A+
✔✔EnCase - ✔✔- from Guidance Software.
- is a very widely used forensic toolkit. allows examiner to connect an Ethernet cable or
null modem cable to a suspect machine and to view the data on that machine.
- prevents the examiner from making any accidental changes to the suspect machine.
- the evidence file is an exact copy of the hard drive.
- calculates an MD5 hash when the drive is acquired. This hash is used to check for
changes, alterations, or errors
- checks for steganography.
✔✔Forensic Toolkit - ✔✔- from AccessData.
- is particularly useful at cracking passwords.
- provides tools to search and analyze the Windows Registry.
- checks for steganography.
✔✔Steganography Tools - ✔✔QuickStego: very easy to use, but very limited.
Invisible Secrets: much more robust, with both a free and a commercial version.
MP3Stego: hides a payload in MP3 files.
Stealth Files 4: works with sound files, video files, and image files.
StegVideo: hides data in a video sequence.
Deep Sound: hides data in sound files.
✔✔Security Accounts Manager (SAM) - ✔✔file in the Windows System directory where
Windows stores hashes of passwords
✔✔Ophcrack - ✔✔Popular hacking tool that depends on rainbow tables. Is usually very
successful at cracking Windows local machine passwords.
✔✔Forensically important Windows directories - ✔✔C:\Windows documents and
settings
C:\Users
C:\Program File
C:\Program Files (x86)
, C:\Users\username\DocumentsRegistry
✔✔Registry hive & supporting files - ✔✔*HKEY_LOCAL_MACHINE\SAM: Sam,
Sam.log, Sam.sav*
HKEY_LOCAL_MACHINE\Security: Security, Security.log, Security.sav
HKEY_LOCAL_MACHINE\Software: Software, Software.log, Software.sav
HKEY_LOCAL_MACHINE\System: System, System.alt, System.log, System.sav
HKEY_CURRENT_CONFIG: System, System.alt, System.log, System.sav, Ntuser.dat,
Ntuser.dat.log
HKEY_USERS\DEFAULT: Default, Default.log, Default.sav
✔✔BASH shell - ✔✔The command prompt in Mac OS, can execute Linux commands.
✔✔Forensically important Mac OS logs, folders, and files - ✔✔/var/log
/var/spool/cups
/private/var/audit
/private/var/VM
/Library/Receipts
/Library/Mobile Documents
*/Users/<user>/.bash_history: BASH shell commands*
var/vm
/Users/
/Users/<user>/Library/Preferences
/Volumes
/Users
/Applications
/Network
*/etc: config files*
/Library/Preferences/SystemConfiguration/dom.apple.preferences.plist
✔✔Forensically important Android directories - ✔✔acct
cache
data
mnt
✔✔Forensic tools for mobile devices - ✔✔Forensic Toolkit and EnCase can both image
a phone
Oxygen Forensics
Cellebrite
MobileEdit
Data Doctor
Device Seizure
Forensic SIM Cloner
✔✔Data Doctor - ✔✔Recovers all Inbox and Outbox data and all contacts data, and has
an easy-to-use interface.