Question: 2 . The initial values of a FAT table are shown below ( All values decimal, - 1 indicates an end of file ) .
The initial values of a FAT table are shown below All values decimal, indicates an end of file
The system uses free blocks starting at the lowestnumbered block, so after writing file A which uses blocks, the table looks like this:
Show the FAT after all of the following additional actions:
a File B is written, using blocks
b File A is deleted
c File C is written using blocks
Focus: File Allocation Table
You got involved in a case where there was an incident in a system. Unfortunately, your forensics knowledge is barely minimum. The computer security expert in your company provided you with an copy of a few entries of the file system directory and the File Allocation Table. Your task is to try to find which file was deleted and which data clusters it was utilizing so the expert may try to recover information from it For now, the only information you have is that the name of the file starts with Y
Directory layout:
Directory entries all values hexadecimal, cluster size is bytes Be sure to have this as a full screen so you see all the values in their appropriate rows.
F C
F D A
EF F F A A
D B AF
File Allocation Table FAT starting from cell
FF FF FF FF FF FF C D E FF FF
Answers you need to provide:
a Full name of the deleted file such as TEST.JPG
b Which data clusters may still contain the deleted data such as
c Which day, month and year the deleted file was created
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
