logo

Crowdly

Browser

Add to Chrome

CMP5372 Applied Cyber Forensics A S2 2025/6

Looking for CMP5372 Applied Cyber Forensics A S2 2025/6 test answers and solutions? Browse our comprehensive collection of verified answers for CMP5372 Applied Cyber Forensics A S2 2025/6 at moodle.bcu.ac.uk.

Get instant access to accurate answers and detailed explanations for your course questions. Our community-driven platform helps students succeed!

Using the SOFTWARE registry hive from the ForensicImage01.E01 evidence file, which web browser is the default installed internet browser? 

0%
100%
0%
0%
View this question

Using the NTUSER.DAT registry hive from the ForensicImage01.E01 to determine the last command executed by user Jethro via the Run window.

Note: NTUSER.DAT is a hidden system file. After exporting it from FTK Imager, ensure that hidden files are enabled in your operating system so the file is visible in the destination folder. If the file does not appear correctly after export, repeat the export to the same folder to ensure it is fully extracted.

0%
100%
0%
0%
0%
View this question

Export the NTUSER.DAT registry hive from user Jethro’s profile folder in the provided disk imageForensicImage01.E01, and determine which of the following files was most recently accessed by the user.

Note: NTUSER.DAT is a hidden system file. After exporting it from FTK Imager, ensure that hidden files are enabled in your operating system so the file is visible in the destination folder. If the file does not appear correctly after export, repeat the export to the same folder to ensure it is fully extracted.

0%
0%
0%
100%
0%
View this question

Using the NTUSER.DAT registry hive from the ForensicImage01.E01 evidence file, which of the following URLs was the last typed in Internet Explorer by user Jethro?

Note: NTUSER.DAT is a hidden system file. After exporting it from FTK Imager, ensure that hidden files are enabled in your operating system so the file is visible in the destination folder. If the file does not appear correctly after export, repeat the export to the same folder to ensure it is fully extracted.

0%
0%
0%
100%
0%
View this question

Using the NTUSER.DAT registry file from the ForensicImage01.E01 evidence file, which of the following programs is the most frequently run by the user Jethro?

Note: NTUSER.DAT is a hidden system file. After exporting it from FTK Imager, ensure that hidden files are enabled in your operating system so the file is visible in the destination folder. If the file does not appear correctly after export, repeat the export to the same folder to ensure it is fully extracted.

0%
100%
0%
0%
0%
View this question

Using FTK Imager to analyse the provided disk image, navigate to the Granny user profile and locate the file with the MD5 hash value 6e02a1b80fbe23b5cfd8046d69bb3dee

What is the amount of disk space allocated to this file by the file system (in bytes)?

0%
0%
100%
0%
0%
View this question

Use FTK Imager to determine the size of the acquired disk image ForeniscImage01.E01What is the size of this disk image?

100%
0%
0%
0%
0%
0%
View this question

What is the file slack size of the file Options.doc on Buddy's desktop?

0%
0%
0%
100%
View this question

Use FTK Imager and the provided disk image ForeniscImage01.E01 to determine the MD5 hash value of the given disk image.

0%
0%
100%
0%
0%
View this question

Use FTK Imager and the provided disk image ForeniscImage01.E01 to determine the name of the examiner associated with the given disk image.

What is the name of the examiner associated with the given disk image?

0%
0%
0%
0%
View this question

Want instant access to all verified answers on moodle.bcu.ac.uk?

Get Unlimited Answers To Exam Questions - Install Crowdly Extension Now!

Browser

Add to Chrome