31. A file containing the hash value for every possible password that can be generated from a computer’s keyboard.
32. A cryptographic technique for embedding information in another file for the purpose of hiding the information from
casual observers.
33. A technology designed to recover encrypted data if users forget their passphrases or if the user key is corrupted after a
system failure.
34. The process of hashing all sectors of a file and then comparing them with sectors on a suspect’s disk drive to determine
whether there are any remnants of the original file that couldn’t be recovered.
35. In steganalysis, the file containing the hidden message.
36. The result of an investigation expanding beyond its original description because the discovery of unexpected evidence
increases the amount of work required.
37. The pnrocess of shifting one or more digits in a binary number to the left or right to produce a different value.
38. An AccessData database containing the hash values of known legitimate and suspicious files. It’s used to identify files
for evidence or eliminate them from the investigation if they are legitimate files.
39. Adding bits to a password before it’s hashed so that a rainbow table can’t find a matching hash value to decifer the
password.
40. In steganalysis, the original file with no hidden message.
41.
List and explain the five steganalysis methods described by Neil F. Johnson and Sushil Jajodia.
42. Explain what a digital watermark is and how it’s used with data.
43. Illustrate how an investigator would detect whether a suspect’s drive contains hidden partitions.
44. Describe the process of block-wise hashing.
45. For most forensics investigations, you follow the same general procedure. Summarize the steps in the procedure.
46. Describe some of the forensic processes involved in investigating an employee suspected of industrial espionage.
47.
Explain what data hiding is and list techniques used to hide data.
48. Describe what happens if a FAT partition containing bad cluster is converted to an NTFS partition, and how you miss
evidence that’s being hidden.
49. Explain how bit-shifting, and related techniques, are used to hide data.
50. Why is it important to validate forensic data, and why are advanced hexadecimal editors necessary for this process?