100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

NWIT263 Midterm (Chapters 5-7) Exam Questions With Correct Answers.

Rating
-
Sold
-
Pages
5
Grade
A+
Uploaded on
15-01-2025
Written in
2024/2025

NWIT263 Midterm (Chapters 5-7) Exam Questions With Correct Answers. Explain the differences in resource and data forks used in macOS. - AnswerThe data fork stores a file's actual data and the resource fork contains file metadata and application information. Which of the following is the main challenge in acquiring an image of a system running macOS? (Choose all that apply.) - Answerb. Vendor training is needed. d. You need special tools to remove drives from a system running macOS or open its case. To recover a password in macOS, which tool do you use? - Answerc. Keychain Access What are the major improvements in the Linux Ext4 file system? - AnswerIt added support for partitions larger than 16 TB, improved management of large files, and offered a more flexible approach to adding file system features. How does macOS reduce file fragmentation? - AnswerBy using clumps, which are groups of contiguous allocation blocks Linux is the only OS that has a kernel. True or False? - AnswerFalse Hard links work in only one partition or volume. True or False? - AnswerTrue Which of the following Linux system files contains hashed passwords for the local system? - Answerd. /etc/shadow Which of the following describes the superblock's function in the Linux file system? (Choose all that apply.) - Answerb. Specifies the disk geometry and available space c. Manages the file system, including configuration information What's the Disk Arbitration feature used for in macOS? - AnswerIt's used to disable and enable automatic mounting when a drive is connected via a USB or FireWire device. In Linux, which of the following is the hom

Show more Read less
Institution
NWIT 263
Course
NWIT 263









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
NWIT 263
Course
NWIT 263

Document information

Uploaded on
January 15, 2025
Number of pages
5
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

©BRIGHSTARS 2024/2025 ALL RIGHTS RESERVED.




NWIT263 Midterm (Chapters 5-7) Exam
Questions With Correct Answers.



Explain the differences in resource and data forks used in macOS. - Answer✔The data fork
stores a file's actual data and the resource fork contains file metadata and application
information.
Which of the following is the main challenge in acquiring an image of a system running macOS?
(Choose all that apply.) - Answer✔b. Vendor training is needed.
d. You need special tools to remove drives from a system running macOS or open its case.

To recover a password in macOS, which tool do you use? - Answer✔c. Keychain Access

What are the major improvements in the Linux Ext4 file system? - Answer✔It added support for
partitions larger than 16 TB, improved management of large files, and offered a more flexible
approach to adding file system features.

How does macOS reduce file fragmentation? - Answer✔By using clumps, which are groups of
contiguous allocation blocks

Linux is the only OS that has a kernel. True or False? - Answer✔False

Hard links work in only one partition or volume. True or False? - Answer✔True
Which of the following Linux system files contains hashed passwords for the local system? -
Answer✔d. /etc/shadow
Which of the following describes the superblock's function in the Linux file system? (Choose all
that apply.) - Answer✔b. Specifies the disk geometry and available space
c. Manages the file system, including configuration information

What's the Disk Arbitration feature used for in macOS? - Answer✔It's used to disable and enable
automatic mounting when a drive is connected via a USB or FireWire device.

In Linux, which of the following is the home directory for the superuser? - Answer✔b. root


1|Page

, ©BRIGHSTARS 2024/2025 ALL RIGHTS RESERVED.

Which of the following certifies when an OS meets UNIX requirements? - Answer✔c. The Open
Group
On most Linux systems, current user login information is in which of the following locations? -
Answer✔d. /var/log/utmp

Hard links are associated with which of the following? - Answer✔b. A specific inode

Which of the following describes plist files? (Choose all that apply.) - Answer✔a. You must
have a special editor to view them.
c. They're preference files for applications.
Data blocks contain actual files and directories and are linked directly to inodes. True or False? -
Answer✔True

Which of the following is a new file added in macOS? (Choose all that apply.) - Answer✔c.
/var/db/diagnostics
d. /var/db/uuid.text
Forensics software tools are grouped into _________ and _______________ applications. -
Answer✔GUI, command-line
According to ISO standard 27037, which of the following is an important factor in data
acquisition? (Choose all that apply.) - Answer✔a. The DEFR's competency
c. Use of validated tools

An encrypted drive is one reason to choose a logical acquisition. True or False? - Answer✔True
Hashing, filtering, and file header analysis make up which function of computer forensics tools?
- Answer✔a. Validation and verification
Hardware acquisition tools typically have built-in software for data analysis. True or False? -
Answer✔False; most are used only for acquisition.
The reconstruction function is needed for which of the following purposes? (Choose all that
apply.) - Answer✔a. Re-create a suspect drive to show what happened.
b. Create a copy of a drive for other investigators.
d. Re-create a drive compromised by malware.

List three subfunctions of the extraction function. - Answer✔Answers can include data viewing,
keyword searching, decompressing, carving, decrypting, and bookmarking.

Data can't be written to disk with a command-line tool. True or False? - Answer✔False



2|Page

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Brightstars Havard School
View profile
Follow You need to be logged in order to follow users or courses
Sold
196
Member since
1 year
Number of followers
7
Documents
12190
Last sold
3 days ago
VERIFIED EXAMS AND STUDY GUIDES.

Here, you will find Study Notes, Exam answer packs 100% Guarenteed success.

3.3

31 reviews

5
10
4
4
3
8
2
3
1
6

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions