100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

DFIR (Digital Forensics and Incident Response) – Comprehensive Terminology and Tools Guide – Verified Questions and Answers

Rating
-
Sold
-
Pages
22
Grade
A+
Uploaded on
26-06-2025
Written in
2024/2025

This document serves as an extensive glossary and Q&A-style reference guide for DFIR (Digital Forensics and Incident Response). It includes accurate definitions and explanations for hundreds of key terms, tools, file formats, processes, Linux/Windows commands, memory forensics methods, and incident response protocols. Designed for both learners and professionals, it is ideal for certification prep and practical application in cybersecurity investigations.

Show more Read less
Institution
DFIR
Course
DFIR










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
DFIR
Course
DFIR

Document information

Uploaded on
June 26, 2025
Number of pages
22
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

DFIR questions with accurate answers
/proc/ Ans✓✓✓Linux process files directory. Uses tmpfs


5W1H Ans✓✓✓Documentation outline for how evidence was obtained.
Who, What, When, Where, Why, How


Advanced Static Analysis Ans✓✓✓


AFF image format Ans✓✓✓Image format that stores the imaged disk
as compresses segments for better saving and metadata of the image


Alternate data stream Ans✓✓✓Method of loading more than one data
sector into a single file. Used to hide files. dir /r to display ADS


Alternate Data Streams (ADS) Ans✓✓✓Method of loading more than
one data sector into single file (hiding data within data). Only works
with NTFS


ASCII code Ans✓✓✓a code for representing English characters as
numbers, with each letter assigned a number from 0 to 127


Attrition Ans✓✓✓a wearing down over time


Autopsy tool Ans✓✓✓Forensic Tool kit includes hash lookup, file
carving, metadata extraction, and more

,Autoruns Ans✓✓✓Checks Autorun Registry locations


Autoruns Ans✓✓✓program allows users to see exactly what is starting
up when the computer boots


BAT file Ans✓✓✓contains a series of line commands in plain text that
are executed to perform various tasks, such as starting programs or
running maintenance utilities within Windows


Binary pattern Ans✓✓✓


Binwalk Ans✓✓✓Tool for identifying files and code embedded inside
of firmware images. Windows/Linux


Black holing Ans✓✓✓a place in the network where incoming or
outgoing traffic is silently discarded (or "dropped"), without informing
the source that the data did not reach its intended recipient


BTRFS filesystem Ans✓✓✓Linux file system, space-efficient file
system. Supports compression and snapshots


Bulk Extractor tool Ans✓✓✓Data carver - ignores the file system
structure, the tool can process different parts of a disk in parallel.

, Business Continuity Plan (BCP) Ans✓✓✓A plan that specifies how to
resume not only IT operations but all business processes in the event of a
major calamity


Certutil Ans✓✓✓Enables generation of multiple hash signatures for a
file. Windows OS


Certutil.exe Ans✓✓✓is an extremely flexible command-line utility for
administering Active Directory Certificate Services


CSIRT Ans✓✓✓computer security incident response team - a
formalized or ad-hod team you can call upon to respond to an incident
after it arises


CSV (comma-separated values) Ans✓✓✓File format for transferring
data, which stores fields and records in a plain text file, separated by
commas


Cuckoo Ans✓✓✓A tool that creates a sandbox useful for analyzing
files, especially malware inspection.


Data carving Ans✓✓✓Reassembling files from pieces of raw data,
when no file system metadata is available. Deleted or partially
overwritten files
R319,09
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached


Document also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker Chamberlain School Of Nursing
Follow You need to be logged in order to follow users or courses
Sold
2014
Member since
3 year
Number of followers
1342
Documents
46921
Last sold
16 hours ago
✨ Cracker – Verified Study Powerhouse

Welcome to your shortcut to academic and certification success. I'm Cracker, a trusted top seller I specialize in high-quality study guides, test banks, certification prep, and real-world exam material all tailored to help you pass fast and score high.

3,8

369 reviews

5
162
4
84
3
52
2
22
1
49

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can immediately select a different document that better matches what you need.

Pay how you prefer, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card or EFT and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions