Computer Science

1)Consistency checking analysis is usually much slower than zero-knowledge analysis.

  1. In FAT and NTFS file systems, a __________ is used to map files to specific clusters where they are stored on the disk.
  2. Damage to how data is stored on a disk, such as file system corruption, is the definition of physical damage.
  3. A test system is a functional system compatible with the hard drive from which someone is trying to recover data.
  4. The basic repair tool in Mac OS is _______.
  5. Which operating system uses the ext file system natively?
  6. What is meant by zero-knowledge analysis?
  7. A symbolic link is an inode that links directly to a specific file.


  1. What name is given to a technique for file system repair that involves scanning a disk's logical structure and ensuring that it is consistent with its specification?
  2. A symbolic link in Linux is similar to a ____________.
  3. A(n) __________ is a data structure in the Linux file system that stores all the information about a file except its name and actual data.
  4. With the consistency checking file system repair technique, a computer's file system is rebuilt from scratch using knowledge of an undamaged file system structure.
  5. Windows 2000 and newer Windows operating systems use the __________ file system.
  6. Forensically scrubbing a file or folder may involve overwriting data with random characters seven times.
  7. The purpose of file carving is to extract the data from a single file from the larger set of data, that is, the entire disk or partition.
  8. An environment that has a controlled level of contamination, such as from dust, microbes, and other particles is the definition of a __________.
  9. Logical damage to a file system is more common than physical damage.
  10. Paige is attempting to recover data from a failed hard disk. She removed the failed drive from the system on which it was installed, and then connected it to a test system. She made the connection by simply connecting the data and power cables but did not actually install the failed drive. What step should she perform next?
  11. The Linux/UNIX command __________ can be used to search for files or contents of files.
  12. In Windows, files that are moved to the Recycle Bin are permanently deleted.
  13. Which file recovery tool works in Linux and Mac OS, and in Windows if you compile the source code?
  14. Linux file systems use hard links and symbolic links.
  15. The two NTFS files of most interest to forensics are the Master File Table (MFT) and the __________.
  16. Clusters in a Windows NTFS system are more likely to be overwritten as more time elapses after deletion.


  1. Linux stores file content in blocks, which are similar to clusters in Windows NTFS.


