The Windows Registry is organized into five sections. The __________ section is very critical to forensic investigations. It has profiles for all the users, including their settings.
Start studying Computer Forensics Chapter 8. Learn vocabulary, terms, and more with flashcards, games, and other study tools.
The term Disk Operating System (DOS) describes memory is allocated based on the last-in, first-out (LIFO) principle.
The term dump refers to the act of ensuring the data that is extracted is consistent.
Dynamic memory for a program comes from the heap segment; a process may use a memory allocator such as malloc to request dynamic memory
A dump is a complete copy of every bit of memory or cache recorded in permanent storage or printed on paper.
All versions of Windows support logging. The Security log contains events logged by Windows system components.