/proc/modules Ans✓✓✓a good example of the Linux method of file
representation; it lists all modules loaded into the kernel
a cyber event Ans✓✓✓The DFIR process begins when THIS occurs
ADS Ans✓✓✓allows more than one data stream to be associated with a
file. These are often misused by attackers to hide executable sections
within an allegedly benign file to bypass traditional detection
mechanisms.
Alert Ans✓✓✓Actionable warning or error message that require
someone's attention
Autopsy Ans✓✓✓an open-source tool that serves as a front-end GUI to
The Sleuth Kit, which is a collection of command line tools that can
perform block device, volume and file system analysis.
Autoruns Ans✓✓✓an example of a tool that can be used to identify
possible startup locations
Black Holing Shunt Ans✓✓✓DDoS traffic from a malicious network
should be dropped and prevented from reaching its destination.
block storage Ans✓✓✓less volatile area
, Browser Forensics Ans✓✓✓a user's searches and other activities and
most of the collected data can be retrieved by analyzing the _________
cache and history files.
Bulk Extractor Ans✓✓✓A tool that attempts to rebuild and recover
files without using a specific file system structure. It is known for its
speed and thoroughness. It ignores file system structure; it can process
different parts of a disk in parallel.
Cached Data Ans✓✓✓Semi-permanent files that are often used to
optimize user experience but can also be used to track user activity, such
as web browser history, recently used or accessed programs and files,
DNS cache, and web browser cookies. Investigating the contents of
THIS can reveal step-by-step activity.
CAINE Live Ans✓✓✓digital forensics toolset that can be booted from
a "live" media, such as USB, and run directly from memory.
Capture format Ans✓✓✓Choose the right ______________.
CMD Ans✓✓✓creating and loading data streams is done via CMD.
Collected disk images Ans✓✓✓these can be mounted directly in Linux
to access its data.