Chapter 5: Working with Windows and CLI Systems

studied byStudied by 1 person
0.0(0)
get a hint
hint

Voltage SecureFile

1 / 137

138 Terms

1

Voltage SecureFile

________ is designed for an enterprise computing environment.

New cards
2

Endpoint Encryption

________ can be used on PCs, laptops, and removable media to secure an entire disk volume.

New cards
3

EFI

________ is designed for x64 computers and uses GUID Partition Table (GPT)- formatted disks.

New cards
4

USB drives

________ and other solid- state drive systems are different, in that memory cells shift data at the physical level to other cells that have had fewer reads and write continuously.

New cards
5

support program

The physical address ________ for accessing more than 4 GB of physical RAM.

New cards
6

NTFS

Clusters are numbered sequentially, starting at 0 in ________ and 2 in FAT.

New cards
7

DOS

If a system has multiple boot OSs, including older ones such as Windows 9x or ________, Ntldr reads BootSect.dos (a hidden file), which contains the address of each OS.

New cards
8

multiple devices

All Windows 8 and 10 boot processes are designed to run on ________, ranging from desktop or laptop systems to tablets and smartphones.

New cards
9

hardware components

The virtual machine recognizes ________ of the host computer its loaded on.

New cards
10

Intel

In an effort to reduce the relationship with firmware, ________ developed UEFI, which defines the interface between a computers firmware and the OS.

New cards
11

large data storage

ReFS is designed to address very ________ needs, such as the cloud.

New cards
12

solid state devices

When dealing with ________, making a full forensic copy as soon as possible is crucial in case you need to recover data from unallocated disk space.

New cards
13

BIOS

________ is designed for x86 computers and is typically used on disk drives with Master Boot Records (MBRs)

New cards
14

track of transactions

The system keeps ________ such as file deleting or saving.

New cards
15

LCN

When data is first written to nonresident files, a(n) ________ address is assigned to the file in the attribute 0x80 field of the MFT.

New cards
16

FAT12

Encrypted files arent part of the ________, FAT16, or FAT32 file systems, so cipher command works only on NTFS systems running Windows 2000 Professional or later.

New cards
17

MS DOS

It was originally designed for ________ 1.0, the first Microsoft OS, used for floppy disk drives and drives up to 16 MB.

New cards
18

Memory cells

________ are designed to perform only 10, 000 to 100, 000 reads /writes, depending on the manufacturers design.

New cards
19

Boot.ini

________ specifies the Windows XP path installation and contains options for selecting the Windows version.

New cards
20

EFS

When ________ is used in Windows 2000 and later, a recovery certificate is generated and sent to the local Windows administrator account.

New cards
21

Tracks

________: Concentric circles on a disk platter where data is located.

New cards
22

Subkey

________: A key displayed under another key, similar to a subfolder in Windows or File Explorer.

New cards
23

Logical Cluster Numbers

________ (LCNs): Are sequentially numbered from the beginning of the disk partition, starting with the value 0.

New cards
24

unique identity

Windows changes the filename and moves the file to a subdirectory with a(n) ________ in the Recycle Bin.

New cards
25

boot selection

When the ________ is made, Ntldr runs NTDetect.com, a 16- bit real- mode program that queries the system for device and configuration data, and then passes its findings to Ntldr.

New cards
26

digital forensics

In ________, virtual machines make it possible to restore a suspect drive on a virtual machine and run nonstandard software the suspect might have loaded, for example.

New cards
27

Recovery Key Agent

To recover an encrypted EFS file, a user can e- mail it or copy the file to the administrator, who can then run the ________ function to restore the file.

New cards
28

File System

________: Gives an OS a road map to data on a disk.

New cards
29

ASCII data

It contains ________, Unicode data, and the date and time of deletion for each file or folder.

New cards
30

hard drive

When data is deleted on a(n) ________, only the references to it are removed, which leaves the original data in unallocated disk space.

New cards
31

Disk Space

Unallocated ________: The area of the disk where the deleted file resides.

New cards
32

Windows Vista

In ________ and later, the boot process uses a boot configuration data (BCD) store.

New cards
33

cluster locations

A run- list is maintained in the MFT of all ________ on the disk for nonresident files.

New cards
34

disk partitions

It supports ________ with a maximum storage capacity of 4 GB.

New cards
35

Windows stores

________ information about the original path and filename in the Info2 file, which is the control file for the Recycle Bin.

New cards
36

guest OS

The ________ is limited by the host computers OS, which might block certain operations.

New cards
37

File System

Gives an OS a road map to data on a disk

New cards
38

Geometry

Refers to a disks logical structure of platters, tracks, and sectors

New cards
39

Head

The device that reads and writes data to a drive

New cards
40

Tracks

Concentric circles on a disk platter where data is located

New cards
41

Cylinder

A column of tracks on two or more disk platters

New cards
42

Sector

A section on a track, usually made up of 512 bytes

New cards
43

Zone Bit Recording (ZBR)

It is how most manufacturers deal with a platters inner tracks having a smaller circumference (and, therefore, less space to store data) than its outer tracks

New cards
44

Track density

The space between each track

New cards
45

Areal density

The number of bits in one square inch of a disk platter

New cards
46

Head and cylinder skew

Used to improve disk performance

New cards
47

Clusters

Storage allocation units of one or more sectors

New cards
48

Logical Addresses

Cluster numbers

New cards
49

Partition

A logical drive

New cards
50

File Allocation Table (FAT)

The file structure database that Microsoft designed for floppy disks

New cards
51

Drive Slack

Composed of the unused space in a cluster between the end of an active files content and the end of the cluster

New cards
52

File Slack

The remaining sectors in the last assigned cluster

New cards
53

Unallocated Disk Space

The area of the disk where the deleted file resides

New cards
54

Partition Boot Sector

The first data set on an NTFS disk

New cards
55

Master File Table

The first file on an NTFS disk

New cards
56

Metadata

Records in the MFT

New cards
57

Resident Files

All information stored in the MFT record

New cards
58

Logical Cluster Numbers (LCNs)

Are sequentially numbered from the beginning of the disk partition, starting with the value 0

New cards
59

Encrypting File System (EFS)

added by Microsoft as optional built-in encryption to NTFS when they introduced Windows 2000

New cards
60

cipher and copy

These two commands are available from a command prompt

New cards
61

Resilient File System (ReFS)

With the release of Windows Server 2012, Microsoft created a new file system called __________.

New cards
62

Registry

A database that stores hardware and software configuration information, network connections, user preferences, and setup information

New cards
63

Registry

A hierarchical database containing system and user information

New cards
64

Registry Editor

A Windows utility for viewing and modifying data in the Registry

New cards
65

Regedit and Regedt32

Two Registry Editors

New cards
66

Key

Folders in each HKEY

New cards
67

Subkey

A key displayed under another key, similar to a subfolder in Windows or File Explorer

New cards
68

Value

A name and value in a key; its similar to a file and its data content

New cards
69

Default value

All keys have a ______ that may or may not contain data

New cards
70

Hives

These are specific branches in HKEY_USER and HKEY_LOCAL_MACHINE

New cards
71

Bootmgr.exe

The Windows Boot Manager program controls boot flow and allows booting multiple OSs, such as booting Vista along with XP

New cards
72

Winload.exe

The Windows Vista OS loader installs the kernel and the Hardware Abstraction Layer (HAL) and loads memory with the necessary boot drivers

New cards
73

Winresume.exe

This tool restarts Vista after the OS goes into hibernation mode

New cards
74

NTBootdd.sys

The device driver that allows the OS to communicate with SCSI or ATA drives that arent related to the BIOS

New cards
75

Ntoskrnl.exe

The Windows XP OS kernel, located in the systemroot/Windows/ System32 folder

New cards
76

Hal.dll

The Hardware Abstraction Layer (HAL) dynamic link library, located in the systemroot/Windows/System32 folder

New cards
77

Configuration File

Contains hardware settings, such as RAM, network configurations, port settings, and so on

New cards
78

Virtual Hard Disk File

Contains the boot loader program, OS files, and users data files

New cards
79

Jetico BestCrypt Volume Encryption

_______ provides WDE for older MS-DOS and current Windows systems.

New cards
80

GUID Partition Table (GPT)

EFI is designed for x64 computers and uses ______ –formatted disks.

New cards
81

garbage collector

When data is rotated to another memory cell, the old memory cell addresses are listed in a firmware file called a “______.”

New cards
82

Physical Addresses

Sector numbers.

New cards
83

Partition Gap

The unused space between partitions.

New cards
84

Nonresident Files

All information stored outside MFT record.

New cards
85

virtual cluster number (VCN)

When data is first written to nonresident files, an LCN address is assigned to the file in the attribute 0x80 field of the MFT. This LCN becomes the file’s ______.

New cards
86

Device drivers

_____ contain instructions for the OS for hardware devices, such as the keyboard, mouse, and video card, and are stored in the systemroot\Windows\System32\ Drivers folder.

New cards
87

CMOS

A computer stores system configuration and date and time information in the _____ when power to the system is off.

New cards
88

Bootstrap Process

Tells the computer how to proceed.

New cards
89

FAT12

This version is used specifically for floppy disks, so it has a limited amount of storage space.

New cards
90

FAT16

Developed by Microsoft to handle larger disks, it is still used on older Microsoft OSs, such as MS-DOS 3.0 through 6.22, Windows 95 and Windows NT 3.5 and 4.0.

It supports disk partitions with a maximum storage capacity of 4 GB.

New cards
91

FAT32

When disk technology improved and disks larger than 2 GB were developed, Microsoft released FAT32, which can access larger drives.

New cards
92

exFAT

Developed for mobile personal storage devices, such as flash memory devices, secure digital eXtended capacity (SDCX), and memory sticks.

New cards
93

VFAT

Developed to handle files with more than eight-character filenames and three-character extensions; introduced with Windows 95.

New cards
94

Drive Slack

Composed of the unused space in a cluster between the end of an active file’s content and the end of the cluster.

New cards
95

RAM Slack

The portion of the last sector used in the last assigned cluster.

New cards
96

File Slack

The remaining sectors in the last assigned cluster.

New cards
97

High Performance File System (HPFS)

The NTFS design was partially based on, and incorporated many features from, Microsoft’s project for IBM with the OS/2 operating system; in this OS, the file system was ______.

New cards
98

Unicode

An international data format.

It uses an 8-bit (UTF-8), 16-bit (UTF-16) or a 32-bit (UTF-32) configuration.

New cards
99

ASCII

For Western-language alphabetic characters, UTF-8 is identical to _____.

New cards
100

$Mft

Base file record for each folder on the NTFS volume; other record positions in the MFT are allocated if more space is needed.

New cards

Explore top notes

note Note
studied byStudied by 44 people
Updated ... ago
4.5 Stars(2)
note Note
studied byStudied by 145 people
Updated ... ago
5.0 Stars(4)
note Note
studied byStudied by 144 people
Updated ... ago
5.0 Stars(3)
note Note
studied byStudied by 5 people
Updated ... ago
5.0 Stars(1)
note Note
studied byStudied by 13 people
Updated ... ago
5.0 Stars(1)
note Note
studied byStudied by 9 people
Updated ... ago
5.0 Stars(2)
note Note
studied byStudied by 7 people
Updated ... ago
5.0 Stars(1)
note Note
studied byStudied by 131294 people
Updated ... ago
4.8 Stars(623)

Explore top flashcards

flashcards Flashcard59 terms
studied byStudied by 1 person
Updated ... ago
5.0 Stars(1)
flashcards Flashcard117 terms
studied byStudied by 9 people
Updated ... ago
5.0 Stars(1)
flashcards Flashcard62 terms
studied byStudied by 11 people
Updated ... ago
5.0 Stars(1)
flashcards Flashcard176 terms
studied byStudied by 80 people
Updated ... ago
5.0 Stars(1)
flashcards Flashcard322 terms
studied byStudied by 2 people
Updated ... ago
5.0 Stars(1)
flashcards Flashcard93 terms
studied byStudied by 13 people
Updated ... ago
5.0 Stars(1)
flashcards Flashcard30 terms
studied byStudied by 95 people
Updated ... ago
5.0 Stars(1)
flashcards Flashcard95 terms
studied byStudied by 10 people
Updated ... ago
5.0 Stars(1)