Question: CECS 7 2 3 7 Windows Registry Exercise This exercise is based on the Andrew Blitz Lab Manual 5 th Edition Chapter 5 specifically Sections

CECS 7237 Windows Registry Exercise
This exercise is based on the Andrew Blitz Lab Manual 5th Edition Chapter 5 specifically Sections 5.2 and 5.4. To complete this lab you will need the image file for chapter 5 InCh05.exe
(InCh05.img), FTK Imager and FTK registry viewer. Your instructor will provide a USB with all of
these files. It might also be possible to use regedit instead of FTK registry viewer. Follow the
instructions in the Andrew Blitz Lab Manual 5th Edition Section 5.2 and answer the following
review questions:
Lab 5.2 Examining the SAM Hive
a. The registry contains how many hives?
b. How many user accounts are disabled:
c. The SAM hive uses PIDs to store information on user accounts. True False __. d. Name two SID values which indicate whether an account was created automatically.
e. The keys property pane shows when user accounts changed their passwords. True_false_.
Lab 5.4 Examining the ntuser.dat registry file.
a. The ntuser.dat file contains information on multuple account holders. True
False
b. What is the email account for user Denise?
c. The ntuser.dat file contains information on which of the following (choose all that apply):
drive letter designations
personalized desktop settings.
PID key_
MRU devices
d. Password decryption tools need
to retrieve user passwords.
e. In which path is the ntuser dat file found?
CECS 7 2 3 7 Windows Registry Exercise This

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!