CIS 6386 Operating Systems and File System Forensics

Assignment Help Other Subject
Reference no: EM132438789

CIS 6386 - Operating Systems and File System Forensics - University of Central Florida


The scope of this assignment is physical and logical disk structures, general file system identification, volume analysis, and the FAT file system. The basis of any file system begins with the partitioning scheme on the disk coupled with volume creation. In this assignment, you will examine the media with your tool(s) of choice and answer the following questions. In addition, you will provide feedback based on the scenario noted below.

Scenario: The suspect is accused of possessing child cornography (considered contraband) after a fellow employee observed him viewing the images on his computer. The suspect is an IT technician who was interviewed by Human Resources investigators. The suspect stated there is nothing on his computer that would constitute such a "disgusting act." HR investigators examined his primary hard drive and found nothing, but his secondary hard drive (a slaved drive) was seized but not examined yet. They have asked you to examine the hard drive to determine if the suspect is in possession of child cornography graphics (again, simulated contraband). He told investigators that they would not find anything and was certain this was an attempt by a fellow employee to get him fired.

1) There are      physical sectors contained in the forensic image of the media. 

2) The size of the forensic image is approximately       gigabytes (enter a whole number, not a decimal value).

3) The MD5 Hash value of the physical media is     .

4) The SHA1 hash value is      .

5) The master boot record (MBR) is located in physical sector      (enter a numeric value, do not spell the number).

6) The partition table begins at sector offset      .

7) The partition table contains 4entries, and each entry is      bytes in length.

8) The first partition begins in physical sector       and contains       sectors within the volume.

9) The first partition contains the      file system.

10) The file system type is identified by what hexadecimal value?       

11) The file system type as noted in question #10 is located in the partition table atsector offset      

12) For the first partition, the volume name is      .

13) For the first partition, the volume serial number is      .

14) The second partition begins in physical sector      .

15) The second partition contains       sectors within the volume.

16) On the second partition, the file system on the second partition is the       file system.

17) On the second partition, thevolume name is      .

18) On the second partition, thevolume serial number is      .

19) The third partition begins in physical sector      .

20) The third partition contains       sectors within the volume.

21) The file system on the third partition is the       file system.

22) The identifier for the file system on the third partition is hex      

23) On the third partition, the volume name is      .

24) On the third partition, the volume serial number is      .

25) In the first partition, the backup copy of the volume boot record is located in physical sector      .

26) In the second partition, the backup copy of the volume boot record is located in physical sector      .

27) On the third partition, the backup copy of the volume boot record is located in physical sector      .

28) How many user-created files exist on the first partition?      

29) How many user-created files exist on the second partition?      

30) How many user-created files exist on the third partition?      

31) How many sectors per cluster are there on the first partition?      

32) How many sectors per cluster are there on the second partition?      

33) How many sectors per cluster are there on the third partition?      

34) Excluding the first three partitions discussed in this assignment, did you locate any additional partitions in a deleted state (yes or no)?  

35) What is the physical sector number of the volume boot record for the deleted partition?      

36) What type of file system is contained within the deleted partition?      

37) If any partitions were recovered, did you discover any text/document files that may describe the subject's intent to delete data?      

38) The name of the file that contains reference to the subject's intent to delete or conceal data is     .

39) How many contraband graphics (child cornography) did you recover?      

40) For the file POP-CORN.JPG,what is the logical size of this file?      

41) For the file POP-CORN.JPG,what is the physical size of this file?      

42) For the file POP-CORN.JPG,what is the created date and time of this file?      

43) For the file POP-CORN.JPG,what is the last written date and time of this file?      

44) For the file POP-CORN.JPG,what is the last accessed date of this file?      

45) For the file POP-CORN.JPG,the exact text on the box of popcorn is     .

46) For the file POP-CORN.JPG, the starting cluster is     .

47) For the file POP-CORN.JPG,there are      clusters allocated to this file?

48) There are       folders on the deleted partition.

49) There are       sectors per cluster on the volume within the recovered partition?

50) The volume name of the deleted partition is      .

Reference no: EM132438789

Questions Cloud

Explain representation of a group through stereotypes : Who takes issue with it, and why? How have the media makers responded? Explain representation of a group through stereotypes or Othering.
Drug enforcement administration schedule for methamphetamine : What is the Drug Enforcement Administration's (DEA's) schedule for methamphetamines, and what category drug is it, legally?
Incident on a reflective blazed grating : A monochromatic plane wave is incident on a reflective blazed grating (of infinite size) and is diffracted to a single plane wave.
What is consciousness : Explaining the difference between the hard and easy problems of consciousness, and by explaining and responding to Nagel's bat echolocation example.
CIS 6386 Operating Systems and File System Forensics : CIS 6386 Operating Systems and File System Forensics Assignment Help and Solution, University of Central Florida - Homework Help
Identify drug enforcement administration schedule : Describe the medical, clinical, or scientific name for drug that you selected and identify Drug Enforcement Administration schedule that it falls into and why.
Draw a picture of the roller coaster drop : Please draw a picture of the roller coaster drop and calculate the kinetic and potential energy at the top and bottom of each hill.
Calculate the equivalent resistance : Calculate the equivalent resistance. Lastly calculate the voltage drop across each resistor in the circuit.
Observe the life of church and ministry : Discuss one point of disagreement or weakness of the book,Write four observa ons about the book,Observe the life of church and ministry


Write a Review

Other Subject Questions & Answers

  Why more prisons and jails should be privatized

Debate and defend your position on whether Sheriff Arpaio's Tent City should be replicated or abolished.

  How does it serve its role in our system of checks and balan

How does it serve its role in our system of checks and balances? How has the Supreme Court developed?

  Attitudes both positive and negative that come with change

How to communicate change in an organization, Attitudes, both positive and negative, that come with change, Strategies for managing attitudes

  Explain why it is a valuable approach and should be used

Provide support for one of these approaches outlined below and explain why it is a valuable approach and should be used in the teaching of students .

  Describe autozones strategy

Conduct an environmental scan or SWOT analysis of AutoZone's current reality and recommend whether the company's current strategy is poised to succeed.

  Define a white paper to an internal audience

A white paper to an internal audience written to individuals within an organization you work for or are a part of

  Micro perspective and macro perspective

Which has a greater influence on a person’s health: individual choices and actions (micro perspective) or community policies and resource availability (macro perspective)?

  Describe the ideal stage of behavior

HA510 - According to (Behavioral Change Theories, 2019), "with each stage of change, there are different intervention strategies are most effective at moving.

  What could the us learn from south koreas school success

What could the US learn from South Korea's school success? The results of PISA 2012 show that South Korea was in the 5th place in Math and Reading, and 7th place in Science scores.

  Debate between offensive and defensive realists

What is at stake in the debate between offensive and defensive realists? How would this be structured in an essay? What would be the best approach in answering

  Will you terminate care for the patient

What are the ethical considerations in evaluating a patient's failure to adhere to a prescribed therapy? Will you terminate care for this patient?

  Describe the relative costs of each strategy you present

Draft a set of company policies that would help to avoid the loss of more than one key executive in a single crisis. Describe the relative costs of each strategy you present.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd