Question 1mediummultiple choice
Read the full OS and File System Forensics explanation →CHFI OS and File System Forensics • Complete Question Bank
Complete CHFI OS and File System Forensics question bank — all 0 questions with answers and detailed explanations.
Refer to the exhibit. === Linux log excerpt (var/log/syslog) === Jan 12 10:15:32 server1 kernel: [ 1234.5678] EXT4-fs (sda1): recovery complete Jan 12 10:15:33 server1 kernel: [ 1234.5680] EXT4-fs (sda1): mounted filesystem with ordered data mode. Opts: (null) Jan 12 10:15:34 server1 sshd[2345]: Accepted publickey for root from 192.168.1.10 port 54321 ssh2: RSA SHA256:abc... Jan 12 10:15:35 server1 sshd[2346]: Received disconnect from 192.168.1.10 port 54321:11: disconnected by user Jan 12 10:15:36 server1 kernel: [ 1234.5700] EXT4-fs (sda1): 1 orphan inode deleted Jan 12 10:15:37 server1 kernel: [ 1234.5702] EXT4-fs (sda1): 1 orphan inode deleted
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Drag a concept onto its matching description — or click a concept then click the description.
Collecting data from a running system
Collecting data from powered-off media
Copying only active files and metadata
Bit-for-bit copy of entire storage device
Collecting only fragments of unallocated space