WGU D431 DIGITAL FORENSICS FINAL ACTUAL EXAM
QUESTIONS AND ANSWERS SURE A+
✔✔AFM - ✔✔- stores the data and the metadata in separate files
✔✔AFD - ✔✔- stores data and metadata in multiple small files
✔✔EnCase format - ✔✔- a proprietary format that is defined by guidance software for
use in its tool to store hard drive images and individual files
- includes a hash of the file to ensure nothing was changed when it was copied from the
source
✔✔Common Forensic Software Programs - ✔✔- EnCase from guidance software
- forensic toolkit (FTK)
✔✔Forensic Toolkit (FTK) - ✔✔- from access data that is very popular with law
enforcement
- can select what hash to use to verify the drive when you copy it , which features you
want to use on the suspect drive, and how to search
- useful at cracking passwords
✔✔The sleuth kit - ✔✔- a collection of command line tools that are available as a free
download
✔✔Disk Investigator - ✔✔- free utility that comes as a GUI for use with windows os
✔✔Steganography - ✔✔- the art and science of writing hidden messages
- Goal is to hide information so that even if it is intercepted it is not clear that the
information is hidden there
- most common method is to hide messages in pictures
✔✔Payload - ✔✔- the information to be covertly communicated
- aka the message you want to hide information steganography
✔✔Carrier ( carrier file) - ✔✔- the signal, stream, or file in which the payload is hidden
✔✔Channel - ✔✔- type of medium used
, - ex photos, video , or sound files or even an active channel such as VoIP
✔✔Steganography tools - ✔✔- quickstego
- invisible secrets
- MP3Stego
- stealth files 4
- stegVideo
- deep sounds
✔✔Steganalysis - ✔✔The process of analyzing a file or files for hidden content
✔✔Cryptographic hashes - ✔✔- how many systems store passwords
✔✔Rainbow Table - ✔✔List of precomputed valued used to more quickly break a
password since values don't have to be calculated for each password being guessed
✔✔Ophcrack - ✔✔- depend on rainbow tables
- very successful at cracking windows local machine passwords
✔✔Windows file swap - ✔✔- used to augment the RAM
- a special place on the hard drive where items from memory can be temporarily stored
for fast retrieval
✔✔Security log - ✔✔- most important log for forensics
- has both successful and unsuccessful login events
✔✔Application log - ✔✔- contains various events logged by applications or programs
- many applications record their errors here
✔✔System log - ✔✔- contains various events logged by windows system components
- includes events like driver failures
✔✔ForwardedEvents log - ✔✔- used to store events collected from remote computers
- this has data in it only if it has been configured
QUESTIONS AND ANSWERS SURE A+
✔✔AFM - ✔✔- stores the data and the metadata in separate files
✔✔AFD - ✔✔- stores data and metadata in multiple small files
✔✔EnCase format - ✔✔- a proprietary format that is defined by guidance software for
use in its tool to store hard drive images and individual files
- includes a hash of the file to ensure nothing was changed when it was copied from the
source
✔✔Common Forensic Software Programs - ✔✔- EnCase from guidance software
- forensic toolkit (FTK)
✔✔Forensic Toolkit (FTK) - ✔✔- from access data that is very popular with law
enforcement
- can select what hash to use to verify the drive when you copy it , which features you
want to use on the suspect drive, and how to search
- useful at cracking passwords
✔✔The sleuth kit - ✔✔- a collection of command line tools that are available as a free
download
✔✔Disk Investigator - ✔✔- free utility that comes as a GUI for use with windows os
✔✔Steganography - ✔✔- the art and science of writing hidden messages
- Goal is to hide information so that even if it is intercepted it is not clear that the
information is hidden there
- most common method is to hide messages in pictures
✔✔Payload - ✔✔- the information to be covertly communicated
- aka the message you want to hide information steganography
✔✔Carrier ( carrier file) - ✔✔- the signal, stream, or file in which the payload is hidden
✔✔Channel - ✔✔- type of medium used
, - ex photos, video , or sound files or even an active channel such as VoIP
✔✔Steganography tools - ✔✔- quickstego
- invisible secrets
- MP3Stego
- stealth files 4
- stegVideo
- deep sounds
✔✔Steganalysis - ✔✔The process of analyzing a file or files for hidden content
✔✔Cryptographic hashes - ✔✔- how many systems store passwords
✔✔Rainbow Table - ✔✔List of precomputed valued used to more quickly break a
password since values don't have to be calculated for each password being guessed
✔✔Ophcrack - ✔✔- depend on rainbow tables
- very successful at cracking windows local machine passwords
✔✔Windows file swap - ✔✔- used to augment the RAM
- a special place on the hard drive where items from memory can be temporarily stored
for fast retrieval
✔✔Security log - ✔✔- most important log for forensics
- has both successful and unsuccessful login events
✔✔Application log - ✔✔- contains various events logged by applications or programs
- many applications record their errors here
✔✔System log - ✔✔- contains various events logged by windows system components
- includes events like driver failures
✔✔ForwardedEvents log - ✔✔- used to store events collected from remote computers
- this has data in it only if it has been configured