100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
Certified Hacking Forensic Investigator (CHFI) Exam Prep | Already Graded $14.49   Add to cart

Exam (elaborations)

Certified Hacking Forensic Investigator (CHFI) Exam Prep | Already Graded

 0 view  0 purchase
  • Course
  • Classroom
  • Institution
  • Classroom

Certified Hacking Forensic Investigator (CHFI) Exam Prep | Already Graded

Preview 4 out of 398  pages

  • October 22, 2024
  • 398
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • Classroom
  • Classroom
avatar-seller
Examsplug
Certified Hacking Forensic Investigator
(CHFI) Exam Prep | Already Graded


What is the Index.dat file used for? - ✔✔AutoComplete & Redundant information such
as visited URLs, search queries, recently opened files

(* Index.dat is used for redundant information such as AutoComplete information. * Index.dat
can be found in the History folder for Internet Explorer)



Which of the following is true about the swap file? - ✔✔Hidden file in the root directory called
pagefile.sys & Registry path is
HKEY_LOCAL_MACHINE_SYSTEM\CurrentControlSet\Control\Session Manager\Memory
Management

(The swap file can be organized as a contiguous space so fewer I/O operations are required
to read and write. It is a hidden file in the root directory called pagefile.sys.)



Each process of Windows is represented as an _______. - ✔✔Executive process

(Each process on a Windows system is represented as an executive process or EProcess.
EProcess block is a data structure containing attributes of the process and pointers to threads
and process environment blocks.)



What command is used to view EProcess block? - ✔✔dt -a -b -v _EPROCESS

,What is the most important element of EProcess? - ✔✔PEB - Process Environment Block




What are the six stages of process creation? - ✔✔1. Launch .exe: File Execution Options
registry key is checked for debugger value. If yes, process starts over

EProcess object created along with KProcess, PEB, and initial address space

Initial thread created

Windows subsystem is notified of new process and thread

Execution of initial thread starts

Initialization of address space is complete for new process and thread



True or False: The EProcess object is created along with KProcess, PEB, and initial
address space - ✔✔True




What tool can parse memory? - ✔✔Lsproc.pl d:\dumps\test-mem.dmp




What is an important consideration for complete memory dump analysis? - ✔✔Pagefile.sys

(The swap file, called pagefile.sys, is virtual memory. Information in the swapfile must also
be considered when analyzing memory.)



What files contain pool headers? - ✔✔Pooltag.txt

,(Windows memory manager generally allocates memory in 4KB pages. Sometimes, 4K would
be too large and waste memory. So memory manager allocates several pages ahead of time thus
keeping an available pool of memory.)



What is the advantage of PMDump? - ✔✔Dump contents of process memory without
stopping the process



What does HKEY_CURRENT_USER contain? - ✔✔Active, loaded user profile for
currently logged-on user



What does HKEY_USERS hive contain? - ✔✔All users profiles




What does HKEY_LOCAL_MACHINE hive contain? - ✔✔Configuration information for the
system including hardware and software settings



What does HKEY_CURRENT_CONFIG? - ✔✔Hardware profile at startup




What does HKEY_CLASSES_ROOT hive contain? - ✔✔Configuration information relating
to which application is used to open various files on the system



What registry data type indicates raw binary data? - ✔✔REG_BINARY




What registry data type indicates 32-bit integer? - ✔✔REG_DWORD

, What registry data type indicates fixed length text string? - ✔✔REG_SZ




What registry data type indicates variable length text string? - ✔✔REG_EXPAND_SZ



What registry data type indicates multiple strings separated by delimiter? -
✔✔REG_MULTI_SZ




What registry data type indicates no data type? - ✔✔REG_NONE




What registry data type indicates 64-bit integer? - ✔✔REG_QWORD




What registry data type indicates Unicode string naming a symbolic link? - ✔✔REG_LINK



What registry data type indicates series of nested arrays storing a resource list? -
✔✔REG_RESOURCE_LIST




What registry data type indicates series of nested arrays storing a device driver's list? -
✔✔REG_RESOURCE_REQUIREMENTS_LIST




What registry data type indicates series of nested arrays storing a resource list used by
physical hardware device? - ✔✔REG_FULL_RESOURCE_DESCRIPTOR

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller Examsplug. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $14.49. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

85651 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$14.49
  • (0)
  Add to cart