.

Monday, December 31, 2018

Perform a Byte-Level Computer Audit Essay

1. What is the main intend of a software gibe same(p) WinAudit in reckoner rhetoricals? conclude WinAudit is a great free tool that lead give you a comprehensive enamour of the components that make up your system, including nastyware, software and BIOS.2. Which items at heart WinAudits initial report would you abidevass to be of critical importance in a calculator forensic investigating?Answer Computer Name, OS, Security Settings for Windows Firewall, claims, zip Programs, and Installed Programs and Versions.3. Could you run WinAudit from a flash propose or any other external media? If so, why is this important during a computer forensic investigation?Answer Yes, WinAudit is a portable Application. Beca subprogram if youre conducting audits on some(prenominal) computers, having the app on a Flash Drive can make the process some(prenominal) easier and more time efficient.4. Why would you use a tool comparable DevManView bit performing a computer forensic investiga tion?Answer DevManView is an alternative to the beat Device Manager of Windows, which displays all devices and their properties in flat table, instead of tree situationer. In addition to displaying the devices of your local computer, DevManView also allows you view the devices list of another computer on your network, as long as you take on administrator access rights to this computer.5. Which item or items within DevManViews list would you admit to be of critical importance in a computer forensic investigation?Answer Most likely the Hdrives and USB depot devices and/or any other computer hardware on the network.6. What tool analogous to DevMan View is already present in Microsoft Windows systems? Answer WinHEX is similar to DevMan.7. Why would person use a HEX editor in chief during a forensic investigation? Answer To see if the files and data recovered from the hard drive are original and authentic.8. What is the character of a software tool like WinHEX in computer forens ics? Answer Its a tool that can retrieval important and sensitive data that has been deleted. This tool is also apply for editing or whipping the info from the drive.9. What was the proper credit of the file you analyzed using WinHEX? How did you let out it? Answer ??10. Why do you impoverishment to keep evidence untampered? In clubhouse to guarantee good admissibility? Answer For legal reasons. So, the evidence can be used in Court. If the evidence is not authentic, it can be thrown out of court.

No comments:

Post a Comment