Hard Disk and File Systems Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Hard Disk and File Systems flashcards as text
Which Windows registry hive stores the most recently accessed files and applications, useful for establishing user activity timelines?
Answer: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
The RecentDocs registry key tracks files recently opened by the user in Windows Explorer, providing a timeline of file access.
In NTFS, what are Alternate Data Streams (ADS) and why are they forensically significant?
Answer: Additional data attached to a file without appearing in its normal size, used to hide data
ADS allows data to be attached to an NTFS file under a different stream name and is invisible to Windows Explorer, making it a common data-hiding technique.
What does the term 'inode' refer to in Linux/ext4 file systems?
Answer: A data structure containing file metadata such as permissions, timestamps, and block pointers
An inode is a data structure in ext file systems that stores all metadata about a file except its name, including ownership, permissions, and pointers to data blocks.
A forensic examiner uses the 'dd' command to image a drive. What is the significance of the 'bs' (block size) parameter?
Answer: It determines the amount of data read and written per operation, affecting speed and sector alignment
The block size (bs) parameter controls how many bytes dd reads and writes at once; aligning it to the disk's sector size (512 or 4096 bytes) improves accuracy and performance.
What is the Host Protected Area (HPA) on a hard disk drive?
Answer: A hidden area at the end of the disk that is excluded from normal OS disk size reporting
The HPA is a hidden region defined by ATA standard SET MAX ADDRESS commands that the BIOS and OS cannot normally detect, commonly used to hide data from forensic tools.
Which tool is commonly used in Linux forensics to recover deleted files from an ext4 file system by scanning unallocated inode entries?
Answer: extundelete
extundelete is a Linux tool that analyzes ext3/ext4 journal and inode tables to recover deleted files from unallocated space.
What does the MFT entry attribute $DATA contain in NTFS?
Answer: The actual file content or data runs pointing to the file's data clusters
The $DATA attribute in an MFT entry either contains the file's data directly (resident) or data runs that map to the clusters holding the file's content (non-resident).