100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

NWIT 263 Digital Forensics (Quiz 1) Exam Questions With Correct Answers.

Rating
-
Sold
-
Pages
5
Grade
A+
Uploaded on
15-01-2025
Written in
2024/2025

NWIT 263 Digital Forensics (Quiz 1) Exam Questions With Correct Answers. Which hashing algorithms will FTK Imager use when one selects "Verify images after they are created"? - AnswerSHA1 and MD5 Which of the following statements regarding the use of hashing utilities by operating systems is CORRECT? - Answerone must use third-party utilities with Windows but Linux comes with built-in utlities Which of the following best describes an FTK Imager Custom Content Image? - Answerit is a customized image with selected files from a live file system or an existing image Which of the following commands would one run from the Linux shell to verify the integrity of a downloaded Kali .ISO file? - Answersha256sum Which of the following hashes would be considered the most secure? 1. 7d0a8468ed220400c0b8e6f335baa7e070ce880a37e2ac5995b9a97b809026de626da636ac736524 9bb974c719edf543b52ed286646f437dc7f810cc2068375c 2. 54b0c58c7ce9f2a8bee0938 3. 2ea8e8822ad47fa1017ff72f06f3ff6a016851f45c398732bc50c 4. fa26be19de6bff93f70bc2308434e4a440bbad02 - Answer7d0a8468ed220400c0b8e6f335baa7e070ce880a37e2ac5995b9a97b809026de626da636 ac7365249bb974c719edf543b52ed286646f437dc7f810cc2068375c From which location is Recuva NO

Show more Read less
Institution
NWIT 263
Course
NWIT 263









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
NWIT 263
Course
NWIT 263

Document information

Uploaded on
January 15, 2025
Number of pages
5
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

©BRIGHSTARS 2024/2025 ALL RIGHTS RESERVED.




NWIT 263 Digital Forensics (Quiz 1) Exam
Questions With Correct Answers.



Which hashing algorithms will FTK Imager use when one selects "Verify images after they are
created"? - Answer✔SHA1 and MD5
Which of the following statements regarding the use of hashing utilities by operating systems is
CORRECT? - Answer✔one must use third-party utilities with Windows but Linux comes with
built-in utlities

Which of the following best describes an FTK Imager Custom Content Image? - Answer✔it is a
customized image with selected files from a live file system or an existing image
Which of the following commands would one run from the Linux shell to verify the integrity of a
downloaded Kali .ISO file? - Answer✔sha256sum kali-linux-2021.2-installer-amd64.iso
Which of the following hashes would be considered the most secure?
1.
7d0a8468ed220400c0b8e6f335baa7e070ce880a37e2ac5995b9a97b809026de626da636ac736524
9bb974c719edf543b52ed286646f437dc7f810cc2068375c
2.
54b0c58c7ce9f2a8b551351102ee0938
3.
2e99758548972a8e8822ad47fa1017ff72f06f3ff6a016851f45c398732bc50c
4.
fa26be19de6bff93f70bc2308434e4a440bbad02 -
Answer✔7d0a8468ed220400c0b8e6f335baa7e070ce880a37e2ac5995b9a97b809026de626da636
ac7365249bb974c719edf543b52ed286646f437dc7f810cc2068375c

From which location is Recuva NOT able to find deleted files? - Answer✔CDs


1|Page

, ©BRIGHSTARS 2024/2025 ALL RIGHTS RESERVED.

Which of the following image files was created using the de facto forensic image format that is
used today? - Answer✔ForensicImage.E01
After a forensic image is created with FTK Imager, which of the following files stores an "Image
Summary" of the image? - Answer✔ForensicImage.E01.txt
Which of the following can be considered metadata for a Windows Excel file?
1.
the data the file was created
2.
the data the file was last edited
3.

the author of the document - Answer✔all of the above
Which of the following statements regarding RAM Slack is true? (Select two)
1.
it is the space between from the E0F marker and the end of the sector
2.
it consists of data dumped from RAM
3.
it is the space from the E0F marker to the end of the cluster
4.

it is another way of referring to the data in 'memory' - Answer✔it is the space between from the
E0F marker and the end of the sector
it consists of data dumped from RAM
What does it mean when one runs a file on a Windows system and receives a message that "The
publisher could not be verified"? - Answer✔it means that the file does not have a valid digital
signature
Which of the following could a forensics investigator use to prevent evidence media from being
written to by a computer that is creating a forensic image? (Select two)
1.
forensics tape
2.

2|Page

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Brightstars Havard School
View profile
Follow You need to be logged in order to follow users or courses
Sold
196
Member since
1 year
Number of followers
7
Documents
12190
Last sold
3 days ago
VERIFIED EXAMS AND STUDY GUIDES.

Here, you will find Study Notes, Exam answer packs 100% Guarenteed success.

3.3

31 reviews

5
10
4
4
3
8
2
3
1
6

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions