Question

Explain the purpose and structure of files systems Describe Microsoft files systems Explain the structure of...

  • Explain the purpose and structure of files systems
  • Describe Microsoft files systems
  • Explain the structure of NTFS disks
  • List some options for decrypting drives encrypted with whole disk encryption
  • Explain how Windows registry works
  • Describe Microsoft start-up tasks
  • Explain the purpose of a virtual machine
  • Describe available digital software forensics tools
  • List some considerations for digital forensics hardware tools
  • Describe methods for validating and testing forensics tools
0 0
Add a comment Improve this question Transcribed image text
Answer #1

A file system is the way in which files are named and where they are placed logically for storge and retrieval. Without a file system, stored information wouldn't be isolated into individual files and would be difficult to identify and retrieve. As data capacities increase, the organization and accessibility of individual files are becoming even more important in data storage.

Purpose of a File System:

  • Data Creation
  • Data modification
  • Last date of Access
  • Backup

Structure of File system:

Microsoft File System:

Resilient File System(ReFS) condenamed "Protogon", is a Microsoft propietary file system introduced with Windows Server 2012 with the intent of becoming the "next generation" file system after NTFS.ReFS was designed to overcome problems that had become significant over the years since NTFS was cinceived, which are related to how data storage requirements had changed.The key design advantages of ReFS include automatic integrity checking and data scrubbing, removal of the need for running chkdsk, protection against data degradation, built in handling of hard disk drive failure and redundancy, integration of RAID functionality, a switch to copy/aloocate on write for data and meta data updates, handling of very long paths and filenames, and storage virtualization and pooling, including almost arbitrarily sized logical volumes.

How Windows Registry works?

The registry contain information used by windows and your programs. The registry helps the operating system manage the computer, it helps program to use the computer's resources, and it provides a location for keeping custom settings you make in both Windos and the programs. For Example,When you change the Windows desktop, the changes are stored in the Registry. when you see a list of recently opened file that list is stored inthe registry and changes you make to the status bar in wordthey are kept in the registry too.The Registry is essentially a database. Its information is stored on disk for the most part, through dynamic information also exists in the computer's memory. All the information is organized by using a structure similar to folders in the file storage system. The top level of the Registry contains hives, each of which starts with the curious word HKEY.

Microsoft Startup Task:

Purpose of Virtual Machine:

Available Digital Software:

  • SANS SIFT: 64-bit base system, Auto-DFIR package update and customization,Cross compatibility with Linux and Windows, Expanded filesystem support, Option to install the standalone system.
  • CrowdStrike CrowdResponse: Comes with three modules- directory listening, active running module and YARA processing module. Displays application resource information, Verifies the digital signature of the process executable, Scans memory, loaded module files, and on disk files of all currently running processes.
  • The Sleuth Kit: Displys system events through a graphical interface, Offers registry, LNK Files,and EMAIL analyses, supports most common file formats,Ectract data from SMS, call logs,contacts, tango and words with friends and analyses the same.
  • FTK Imager: Comes with Data Preview capability to preview files/folders as well as content in it, Supports Image Mounting, Uses multicore CPUs to parallerize actions, Accesses a shared case database , so a single central database is enough for a single case.

Digital Forensic Hardware Toos:

  • Cellebrite UFED Touch 2
  • Branded Tablet Cellebrite UFED Touch2 or UFED 4PC
  • UFED Physical Aalyzer
  • MSAB XRY/MSAB XRYField
  • MSAB XRY Kiosk
  • Rusolut

Methoda for Validating and Testing Forensic TOOLS:

Add a comment
Know the answer?
Add Answer to:
Explain the purpose and structure of files systems Describe Microsoft files systems Explain the structure of...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • 1. Explain the difference between logical addresses and physical addresses in Microsoft file structures. Answer: 2....

    1. Explain the difference between logical addresses and physical addresses in Microsoft file structures. Answer: 2. To help prevent loss of information, software vendors, including Microsoft, now provide whole disk encryption. This feature creates new challenges in examining and recovering data from drivers. What are four features offered by whole disk encryption tools that forensics examiners should be aware of? Answer: 3. What does the $Secure metadata file contain? Answer: 4. Describe both ways in which file or folder information...

  • Explain what enterprise resource planning (ERP) systems. Outline several of their key characteristics. Describe in reasonable...

    Explain what enterprise resource planning (ERP) systems. Outline several of their key characteristics. Describe in reasonable detail how a company leverages an ERP system and how its operations are improved after installing an ERP system like SAP. Explain how a supply chain management system helps an organization make its operations more efficient What is Upstream and Downstream management of the supply chain? Explain the concept of “Supply Network”, its benefits, and how technology made this concept available Explain the difference...

  • Milestone #1: Pre-Planning Purpose In this milestone your will be working as an analyst and IT...

    Milestone #1: Pre-Planning Purpose In this milestone your will be working as an analyst and IT consultant for Universal Wellness Group (UWG). UWG offers a holistic approach to health care with an emphasis on preventive medicine as well as traditional medical care. In your role as an IT consultant, you will help Universal develop a new information system. Every project before it can officially kick-off needs to have some pre-planning work completed. In this milestone you will perform some pre-planning...

  • TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for...

    TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for all potential types of non-standard inputs that might be exploited by an attacker to subvert a program. 2. Without suitable synchronization of accesses it is possible that values may be corrupted, or changes lost, due to over-lapping access, use, and replacement of shared values. 3. The biggest change of the nature in Windows XP SP2 was to change all anonymous remote procedure call (RPC)...

  • CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male...

    CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male San Bernardino suspect's iPhone 5c. Cook stated: Antiterrorism We are challenging the FBI's demands with the deepes respect for American democracy and a love of our country. We believe it would be in the best interest of everyone to step back and consider the implications While we believe the FBI's intentions are good, if would be wrong for the w e nt to force...

  • Assignment Details The Unit 6 Assignment requires you to consider how effective teams are built. Some...

    Assignment Details The Unit 6 Assignment requires you to consider how effective teams are built. Some considerations in this assignment include the traits of an effective team leader as well as the strategies one would use to recruit team members that would work effectively together. Using material from Chapter 12 of your text as well as the article in the supplemental reading (Rao, 2016), you will write an informative essay sharing best practices for effective team-building. Outcomes evaluated through this...

  • First, read the article on "The Delphi Method for Graduate Research." ------ Article is posted below...

    First, read the article on "The Delphi Method for Graduate Research." ------ Article is posted below Include each of the following in your answer (if applicable – explain in a paragraph) Research problem: what do you want to solve using Delphi? Sample: who will participate and why? (answer in 5 -10 sentences) Round one questionnaire: include 5 hypothetical questions you would like to ask Discuss: what are possible outcomes of the findings from your study? Hint: this is the conclusion....

  • How can we assess whether a project is a success or a failure? This case presents...

    How can we assess whether a project is a success or a failure? This case presents two phases of a large business transformation project involving the implementation of an ERP system with the aim of creating an integrated company. The case illustrates some of the challenges associated with integration. It also presents the obstacles facing companies that undertake projects involving large information technology projects. Bombardier and Its Environment Joseph-Armand Bombardier was 15 years old when he built his first snowmobile...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT