Autopsy and Cyber Triage DFIR Training||Cases and Data Sources Part 3
Quiz
True or False: In a multi-user cluster, all examiners need
to have access to the case directory at the same path (i.e. \\server\cases\ or
Z:\Cases)
Choose only ONE best answer.
A
True
B
False
This answer is correct.
QUESTION 2 OF 10
Autopsy is able to ingest
the following data sources directly:
Choose ALL answers that apply.
·
A
Disk Image or VM file
·
B
Pieces of paper
·
C
Logical files
·
D
Scratched hard drive
platters
This answer is correct.
QUESTION 3 OF 10
True or False: When
adding a data source to Autopsy, in-depth analysis on the data is automatically
performed
Choose only ONE best answer.
A
True
B
False
This answer is correct.
QUESTION 4 OF 10
True or False: The
Autopsy case database stores a full copy of every single file contained within
a data source
Choose only ONE best answer.
A
True
B
False
This answer is correct.
QUESTION 5 OF 10
Autopsy supports many
volume systems, including:
Choose ALL answers that apply.
·
A
DOS
·
B
BSD
·
C
RSVP
·
D
YAJBFS3
·
E
GPT
This answer is correct.
QUESTION 6 OF 10
Autopsy supports many
file system formats, including:
Choose ALL answers that apply.
·
A
FAT32
·
B
YAFFS2
·
C
HFS+
·
D
Ext4
·
E
NTFS
This answer is correct.
QUESTION 7 OF 10
Orphan files in Autopsy are stored under the $OrphanFile folder.
What is an orphan file?
Choose only ONE best answer.
A
A deleted file that no longer has a parent folder.
B
An allocated, but corrupt file
This answer is correct.
QUESTION 8 OF 10
What types of disk images
are currently NOT NATIVELY SUPPORTED by Autopsy
Choose ALL answers that apply.
·
A
SUPER DUPER EXTREME RAID
·
B
Bitlocker
·
C
RAID
·
D
KUBEKLUSTER
This answer is correct.
QUESTION 9 OF 10
True or False: When adding "Local Files and Folders"
to a case in Autopsy, file times are added to the database
Choose only ONE best answer.
A
True
B
False
This answer is correct.
QUESTION 10 OF 10
True or False: When
adding an E01 file to a case within Autopsy, the E01 file is automatically
validated upon import
Choose only ONE best answer.
A
True
B
False
This answer is correct.
Lab Steps
- MD5 (device1_laptop.e01) =
dc176d653c5613e305e831525e874090
- MD5 (device2_mediacard.e01) =
c8343d3976eec2985e7580a2b6321591
We will now begin the
analysis of the hard drive that was found in the dognappers car. At this
point in the scenario, we haven’t searched the house yet and therefore will not
have access to the media card device. So, make sure you do not add that
yet.
1.
Launch Autopsy
2.
Choose “Create New Case”
3. Make
a case with the following information:
1.
Case Name: case1
2.
Base Directory: c:\ (or where ever you'd like to store the
case)
3.
Skip case number and examiner
4.
Add device1_laptop.e01 image as data source.
***** NOTE: Do NOT add device2_mediacard.e01 yet *****
5.
Deselect ALL ingest modules.
- As a reminder, this is not what you’d typically do. But, we are doing
it this way for the course.
6.
Finish Adding Image.
7. Open
the “Data Sources” part of the left-hand tree (we’ll cover this tree more in
the next section).
1. Question: How many volumes does
the disk image have?
2. Question: What is the name of the
unallocated space file in vol1?
3. Question: Right click on vol7 and
choose “File System Details”. What file system is in vol7?
8. In
Windows, open “C:\case1” in a file explorer and observe its contents.
1. Question: What is the database
called?
2. Question: Roughly how big is the
database (in megabytes)?
Lab Quiz




0 comments:
Post a Comment