Which utility, originally created for the Unix platform, copies and converts files using two basic arguments ( if and of )?
Answer: The dd utility
Which software suite provides an Enterprise Edition that specifically supports volatile data analysis on a live Windows system?
Answer: EnCase
Which disk imaging software operates as an extended DOS command shell?
Answer: DriveSpy
What are two common algorithms used to create hash values for drive images?
Answer: MD5 and SHA
Which forensic software suite integrates the dtSearch engine in its searching function?
Answer: FTK
What two software suites are free?
Answer: TCT and TSK
What are two of several vendors of forensic computers?
Answer: Vogon and Digital Intelligence
After creating an image of a drive, what must you do to ensure the copy matches the original?
Answer: Calculate a hash of the image and compare to the original.
You have many factors to consider when choosing appropriate forensic software. Name two.
Answer: Answers can include expected types of investigations, operating system needs and preference, background and training, budget, and status (law enforcement or private organization).
Which utilities provide comprehensive forensic functionality?
Answer: EnCase and FTK