Question: What happens to data in RAM when a Windows system goes into Hibernation? ( CLO 6 , MLO 5 E ) Question 1 options: a
What happens to data in RAM when a Windows system goes into Hibernation?
CLO MLOE
Question options:
a
It is overwritten by HIBERFIL.SYS
b
It is rearranged in RAM.
c
It begins to disappear.
d
It is written to the hard drive.
Question Mandatory point
Listen
Simply put, what is the Windows registry?
CLO MLOA
Question options:
a
A database for Windows configuration files
b
A process which tracks the user's Internet history
c
An area of memory which the CPU interacts with directly
d
A hierarchal structure of Windows artifact files
Question Mandatory point
Listen
What Windows artifact links a user's account to a particular action?
CLO MLOF
Question options:
a
The Date and Time Stamps
b
The Administrator Privilege
c
The Security Identifier
d
The Bitstream Image Hash
Question Mandatory point
Listen
What is NOT true about a spool file?
CLO MLOB
Question options:
a
It remains in the computer for a long time
b
It shows the computer name
c
It shows the printer name
d
It shows the user account that sent the job
Question Mandatory point
Listen
Why is recycling bin one of the first places forensic examiner checks for evidence?
CLO MLOC
Question options:
a
It contains metadata about files in slack space
b
Some users believe files are deleted when placed there
c
It is the final resting place for all deleted files
d
Deleted and overwritten files are always sent through it
Question Mandatory point
Listen
What is Metadata?
CLO MLOD
Question options:
a
Data about data
b
Time and Date data
c
The data about file creation
d
Windows artifact data
Question Mandatory point
Listen
Windows Restore Points are files that
CLO MLOE
Question options:
a
Contain future source data for number of times a system will be restored.
b
Contain previous system and configuration settings
c
Contain metadata about the system registry
d
Are only used when Windows crashes.
Question Mandatory point
Listen
A file that shows if an application was run or installed on a system is called
CLO MLOF
Question options:
a
The installer file
b
The thumbnail file
c
The shadow copy file
d
The prefetch file
Question Mandatory point
Listen
One issue with Date and Time stamps is
CLO MLOF
Question options:
a
They are limited to EST Time Zone
b
They contain unnecessary metadata
c
They are only updated on file modifications
d
They can be spoofed or modified easily
Question Mandatory point
Listen
If a thumbnail is found, but not the image file, it can be concluded that
CLO MLOD
Question options:
a
The image was hosted in cloud storage
b
The image never existed
c
The image once existed on the system
d
The image was downloaded remotely
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
