NTFS
1.pdf~~~~~~~~~~~~~~~~~~~~~~~~~!!!!!!!!!!!!!!!!!!!!@(&*#########################(@)@)@~~~~~~~~~~~~)))))))))))))))
Exam
NTFS
1.pdf~~~~~~~~~~~~~~~~~~~~~~~~~!!!!!!!!!!!!!!!!!!!!@(&*#########################(@)@)@~~~~~~~~~~~~)))))))))))))))
Exam 1.pdf~~~~~~~~~~~~~~~~~~~~~~~~~!!!!!!!!!!!!!!!!!!!!@(&*#########################(@)@)@~~~~~~~~~~~~)))))))))))))))
NTFS Exam 1
MFT - ANS-Master File Table
- Every File and Folder has at least one record
-MFT record size - ANS-Always 1024 bytes or 2 sectors
-MFT record header size (depending on the OS) - ANS-48 or 56 bytes
MFT attributes - ANS-Could be name of file, standard information, data, dates. Possible
to have one or more of the same attribute type.
MFT record - ANS-MFT entry. Each has a number, starting at 0.
NTFS Cluster size - ANS-4096 bytes or 8 sectors or ~4kB
(Technically variable - check VBR)
Allows for encryption and compression
Logical Cluster Number (LCN) - ANS-Where is $MFT?
Sequence Number of MFT record - ANS-Identifies how many times a record has been
used (high if record has been deleted and reused)
Hard Link Count of MFT record - ANS-Number of pointers to record
Physical Record size - ANS-1024 bytes
Base File Reference of MFT record - ANS-Number in list of records (starting at 0)
Update Sequence of MFT record - ANS-Identifies displaced array. NOT the displaced
bytes.
2 bytes
The first record (in multiple of one file) is called - ANS-Base record (Number 0)
Any other records other than the first (in multiple of one file) is called - ANS-Extension
records (Number 1+)
MFT record structure - ANS-Header > Attribute > Attribute >.. unused
NTFS Exam
NTFS
1.pdf~~~~~~~~~~~~~~~~~~~~~~~~~!!!!!!!!!!!!!!!!!!!!@(&*#########################(@)@)@~~~~~~~~~~~~)))))))))))))))
Exam
NTFS
1.pdf~~~~~~~~~~~~~~~~~~~~~~~~~!!!!!!!!!!!!!!!!!!!!@(&*#########################(@)@)@~~~~~~~~~~~~)))))))))))))))
Exam 1.pdf~~~~~~~~~~~~~~~~~~~~~~~~~!!!!!!!!!!!!!!!!!!!!@(&*#########################(@)@)@~~~~~~~~~~~~)))))))))))))))