Unit 2: Hard Disks, File Systems and Data Acquisition - Subjective Questions

CSC303 — Digital Forensics • Practice Questions with Detailed Answers

20 questions

1

Describe the different types of disk drives used in computer systems and explain their key characteristics.

2

Explain the logical structure of a disk, including tracks, sectors, cylinders, and clusters.

3

Describe the booting process of the Windows operating system in detail.

4

Explain the booting process of Linux and Mac operating systems and highlight the key differences from Windows.

5

Describe the file systems used by the Windows operating system (FAT and NTFS) and their characteristics.

6

Explain the file systems used in Linux (ext2/ext3/ext4) and macOS (HFS+ and APFS).

7

What is Autopsy and The Sleuth Kit (TSK)? Explain how they are used to examine a file system.

8

Distinguish between MBR and GPT partitioning schemes.

9

Understand and explain various storage systems such as RAID, NAS, SAN, and cloud storage.

10

Explain the common encoding standards (ASCII, Unicode/UTF) and the role of hex editors in digital forensics.

11

Define file signatures and explain their importance in file identification during forensic analysis.

12

Explain the fundamentals of data acquisition in digital forensics, including the types of acquisition.

13

Describe the data acquisition methodology and the standard steps followed to acquire digital evidence.

14

What is a write blocker? Explain its types and importance in the acquisition process.

15

Explain the role of hashing in maintaining evidence integrity during data acquisition.

16

Explain the steps involved in preparing an image file for forensic examination.

17

Compare HDD and SSD from a digital forensics perspective, highlighting the challenges SSDs pose.

18

Describe the concept of slack space and its forensic significance.

19

Explain the difference between live acquisition and static (dead) acquisition, and when each is used.

20

Describe the NTFS Master File Table (MFT) and explain why it is important in forensic investigations.