Hard Disk and File Systems Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Hard Disk and File Systems flashcards as text
What does the NTFS $LogFile record, and why is it forensically valuable?
Answer: Transactional metadata changes to the file system, allowing reconstruction of recent file operations
The NTFS $LogFile is a circular transaction log that records metadata changes; forensic tools can parse it to reconstruct file creation, deletion, and renaming events even after file system operations.
In ext4, what is the 'journal' and what mode provides the strongest data integrity?
Answer: A write-ahead log for file system metadata; 'data=journal' mode journals both metadata and data blocks
ext4's journal records operations before committing them; 'data=journal' mode (writeback < ordered < journal) provides the highest integrity by journaling both data and metadata.
A suspect's drive shows a partition type code of 0x07 in the MBR partition table. What file system does this typically indicate?
Answer: NTFS or exFAT
Partition type code 0x07 is assigned to NTFS (and exFAT) partitions in the MBR partition table scheme.
What is 'timeline analysis' in file system forensics, and which three NTFS timestamps are primarily used?
Answer: Chronologically ordering file system events; primarily uses Modified, Accessed, and Created (MAC) times from $STANDARD_INFORMATION
Timeline analysis arranges file system events chronologically using MAC times (Modified, Accessed, Created) along with the MFT entry change time to reconstruct attacker or user activity.
Which technique do attackers use to manipulate NTFS timestamps to make malicious files appear to have existed long before an attack?
Answer: Timestomping
Timestomping involves modifying the MAC timestamps in an NTFS file's $STANDARD_INFORMATION attribute to disguise when a file was created or modified.
What is 'slack space' and which two types are relevant to NTFS forensics?
Answer: Unused space within the last cluster of a file and unused bytes in the last sector of that cluster; file slack and RAM slack
File slack is the unused space between the end of a file's logical data and the end of its last allocated cluster; RAM slack (within the sector) may contain remnant memory data, both can hold hidden or residual data.
When performing a forensic hash verification of a disk image, which combination of algorithms is considered best practice to minimize collision risk?
Answer: MD5 and SHA-256 together
Using both MD5 (for legacy compatibility) and SHA-256 (for cryptographic strength) together minimizes the risk of an undetected collision or tampering in forensic evidence.