Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

1 . What s the volume serial number of the GCFI - Bart _ Jones.E 0 1 image? Hint: In FTK Imager, click the GCFI

1. Whats the volume serial number of the GCFI-Bart_Jones.E01 image? Hint: In FTK Imager, click the GCFI-bj01[NTFS] folder at the left. Then examine the Properties pane at bottom left. Also, if the pane at the bottom left shows Custom Content Sources pane, you need to click the Properties tab at the very bottom to show the Properties pane.
1. FIRESTARTER
2.2,056,257
3.184E-912E
4. Cant be determined from the evidence
2. What date was the root folder in the GCFI-Bart_Jones.E01 image last accessed? Hint: In FTK Imager, click the root folder at the left and then review the Date Modified column at the right.
1.3/22/2009
2.4/25/2017
3.1/31/2004
4.5/22/2018
3. What deleted Office files were found in the GCFI-Bart_Jones.E01 images RECYCLED BIN folder? Hint: these files are in the Plans folder in the screenshot below.
1.!ATE1.XLS
2. CV.DOC
3. Burninator1.docx, Burninator2.doc, Burninator3.doc, and Burninator4.doc
4. Special Project A-Victor-rev01.docx, Special Project A-Whiskey-rev01.docx, Special Project A-Xray-rev01.docx, Special Project A-Yankee-rev01.docx, and Special Project A-Zebra1-rev01.docx
4. What types of nonsystem files are in the RECYCLED BIN\Pleasure folder? (Choose all that apply.) Hint: Examine the $RYHYWJ0 folder as well as all the subfolders under this folder.
1..doc and .docx files
2..xls and .xlsx files
3..gif files
4..jpg files
5. Which two types of file hashes are included in the Firestarter File Hashes.csv file?

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access with AI-Powered Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Students also viewed these Databases questions