Шукаєте відповіді та рішення тестів для CMP5372 Applied Cyber Forensics A S2 2025/6? Перегляньте нашу велику колекцію перевірених відповідей для CMP5372 Applied Cyber Forensics A S2 2025/6 в moodle.bcu.ac.uk.
Отримайте миттєвий доступ до точних відповідей та детальних пояснень для питань вашого курсу. Наша платформа, створена спільнотою, допомагає студентам досягати успіху!
Using FTK Imager, examine the provided disk image ForeniscImage01.E01 and determine when the SYSTEM registry hive file was last accessed.
Examine the disk image and locate the file corresponding to MFT Record Number 1. What is the size of this file?
An 8-byte FILETIME timestamp has been encoded starting at hexadecimal offset CB868; locate this offset and determine the UTC time (Little endian Format).
Using the SAM registry hive from the ForensicImage01.E01 evidence file, which of the follwing users last login to the computer?
Using the SAM registry hive from the ForensicImage01.E01 evidence file, when was the last failed login attempt by user Granny?
Using the SAM registry hive from the ForensicImage01.E01 evidence file, which user account has been most frequently used to log in to this computer?
Using the SYSTEM registry hive from the ForensicImage01.E01 evidence file, what is the active time zone currently set on the computer?
Using the SYSTEM registry hive from the ForensicImage01.E01 evidence file, what was the last USB storage device connected to the computer?
Using the SYSTEM registry hive from the ForensicImage01.E01 evidence file, when was the last recorded shutdown time of the computer?
Using the SOFTWARE registry hive from the ForensicImage01.E01 evidence file, when was the software ‘Adobe AIR’ installed on the computer?