Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CYSA+ Chapter 7 (1)

Rating
-
Sold
-
Pages
2
Grade
A+
Uploaded on
01-08-2024
Written in
2024/2025

Exam of 2 pages for the course CySA+ at CySA+ (CYSA+ Chapter 7 (1))

Institution
CySA+
Course
CySA+

Content preview

CYSA+ Chapter 7
What are three important things that a digital forensics workstation should have? -
ANS-A powerful, multicore CPU, plenty of ram, and lots of fast, reliable storage.

What are write blockers? - ANS-Things that ensure that drives connected to a forensic
system or device cannot be written to.

What is the purpose of an imaging utility? - ANS-It creates a forensic image of a
complete disk, a disk partition, or a logical volume.

What is slack space? - ANS-The space left when a file is written.

What are packers? - ANS-A tool used in many malware packages intended to protect it
from reverse engineering.

What are the steps to the forensics process? - ANS-1. Determine what you are trying to
find out.
2. Outline the locations and types of data that you will need.
3. Document and review your plan.
4. Acquire and preserve evidence.
5. Perform the initial analysis.
6. Use the initial analysis to guide further work.
7. Report on the findings of the investigation.

What information can be found in the Windows Registry? - ANS-Information about files
and services, locations of deleted files, evidence of applications being run.

What information can be found in the Autorun keys? - ANS-Programs set to start on
startup (often associated with malware or compromise).

What information can be found in the Master File Table (MFT)? - ANS-Details of
inactive/removed records.

What information can be found in the Event logs? - ANS-Logins, service start/stop,
evidence of applications being run.

What information can be found in the INDX files and change logs? - ANS-Evidence of
deleted files, MAC timestamps.

Document information

Uploaded on
August 1, 2024
Number of pages
2
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
CA$12.13
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Thumbnail
Package deal
CySA+
-
31 2024
CA$ 376.09 More info

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Ace360PRO Stuvia
View profile
Follow You need to be logged in order to follow users or courses
Sold
245
Member since
1 year
Number of followers
2
Documents
10541
Last sold
1 day ago

4.8

89 reviews

5
76
4
9
3
3
2
1
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions