|
Notice!
Always refer to the module on your for the most accurate and up-to-date information.
Quiz 1
1. The Windows Registry is defined as- Central relational database
- SQL database
- Central hierarchical database
- Flat file
- Link Files
- Property lists
- Log Files
- Configuration and Initialization files
- System Information
- Application specific information
- Disk structure information
- user information
- Determining the number of partitions on a drive
- Determining cluster size
- Validating findings through an investigation
- looking up a phone number
- installed programs
- all of these
- user account information
- devices attached to the computer
- only matters if it is a Windows 7 computer
- has nothing to do with the registry
- will determine the type of information you are looking for
- will NOT determine the type of information you are looking for
- Sub-Keys
- Data
- All of these
- Keys
- Hives
- Values
- user Keys (UK)
- Handle Keys (HK)
- File Keys (FK)
- Block Keys (BK)
- Security
- Hardware
- System
- Sam
- Software
- Binary Data
- Hex Data
- SL Data
- String Data
- PTUser.reg and user.Dat
- NTUser.Dat and UsrClass.Dat
- None of the above
- Amcache and Sam
- security
- software
- Sam
- All of these
- AmCache
- system
- Volume root\Windows\Sam\config
- Volume root\WindowsNT\system32\config
- Volume root\system32\user\config
- Volume root\Windows\system32\config
- NTUser.dat and Software
- Sam and System
- Sam and Security
- NTUser.dat and USRClass.dat
- Hex editor
- Specialized tool used to view the Window Registry
- Registry hive sub-key
- Older type of Windows registry prior to Windows 95
- Windows
- Select
- System
- Microsoft
- Sam
- Software
- System
- Security
- Security
- System
- Software
- Sam
- Both A and B
- HKEY_LOCAL_MACHINE-SAM SUBKEY
- HKEY_LOCAL_MACHINE—HARDWARE SUBKEY
- None of these
- HKEY_LOCAL_MACHINE-SYSTEM SUBKEY
- HKEY_CURRENT_USER
- Sam
- Both Security and Software
- security
- software
- system
- Both Sam and security
- The Run Sub Once subkey
- User Assist
- The Run MRU subkey
- Recent Docs subkey
- Recently run applications
- Search terms typed into Windows Explorer
- Programs run at startup
- Web Addresses typed into the Internet Explorer Address Bar
- Run
- User Assist
- Recent Applications
- Typed URLs
- Run Once
- User Assist
- Recent Apps
- Run MRU
- Run MRU
- Recent Apps
- Run
- Run Once
- Run MRU
- ComDlg32 OpenSavePidMRU
- Recent Docs
- Recent Apps
- Run
- Run MRU
- WordWheel Query
- Run Once
- Keeps track of URL typed into the Internet Explorer Address Bar
- Keeps track of Files, Directories, or programs accessed by typing a File path into Windows Explorer
- comdlg 32
- Runs at startup
- programs or applications launched through the Windows runbox
- User-specific programs that are set to run at startup with no interaction from
- Recently used Microsoft Office Documents
- created when a user types a path to a directory, file, or application into Windows Explorer.
- ComDlg32
- Recent Apps
- Run MRU
- WordWheel uery
- Information about files and applications recently accessed by a user
- information about the users internet accounts and browser history
- Programs set to Run at startup by a user
- information about each user such as login information, login password hashes, and group information
- Issuing identifier-Domain authority-Machine identifier
- Issuing authority- Machine/domain identifier- Relative identifier
- user name – Profile path- User directory
- All of the above
- Users
- Domains
- Groups
- Account
- User
- Domain
- Group
- Machine
- Relative Identifier
- log on count
- password hash
- last logon time
- Names
- Accounts
- User
- Domains
- last logon date and time
- number of failed logon’s
- username and password hash
- log on count
- all of the above
- This key maintains a list of all the values typed into the Run box on the Start menu
- This key tracks user searches
- This key shows programs that run at startup
- User logon information and last logged on user
- AutoStart locations
- values typed into the Run box on the Start menu
- A specific executable used to open the files
- Comdlg 32
- Classes
- LogonUI
- Run
- Run Key
- RunMRU
- Installed printers
- Comdlg 32
- Run Once
- Winlogon
- Windows
- Current Version
- Domain user account information
- Wireless network dates and times and gateway MAC address
- Evidence of program execution
- User account information
- Mount points and Mountspoints2
- Mountpoints2 and RunMRU
- Devices and EMD Management
- USBStore and USB
- Control
- Prefetch
- Services
- Select
- USBstore
- select
- control
- Windows
- is not a subkey in the system hive
- Indicates when the system needs service
- run automatically when the system is booted, and are started by the system and with no interaction from the user
- Tracks USB Devices
- Select
- prefetchParameters
- Windows
- Controlset
- Memory Management
- Crash Control
- select
- shutdown
- user account information
- programs set to run at startup
- prefetch settings
- USB device connection and disconnection dates and times
- All of these
- File Path
- None of these
- Last Modified Time
- File Size
- Program execution by a specific user
- Nothing
- Program execution but not by a specific user
- A change to the file MFT record
- Folders or Directories within the Windows file system
- Programs run at startup
- File Times
- Recently used applications
- The NTUser.dat Hive File
- The System Hive File
- The AmCache Hive File
- The Sam File