Guide to Computer Forensics and Investigations, 5th Edition,
Ch. 10 Solutions-1
Chapter 10 Solutions
Review Questions
1. Virtual Machine Extensions (VMX) are part of which of the following?
2. You can expect to find a type 2 hypervisor on what type of device? (Choose all that
apply.)
3. Which of the following file extensions are associated with VMware virtual
machines?
4. In VirtualBox, a(n) ____________________ file contains settings for virtual hard
drives.
5. The number of VMs that can be supported per host by a type 1 hypervisor is
generally determined by the amount of __________ and ______________.
6. A forensic image of a VM includes all snapshots. True or False?
7. Which Registry key contains associations for file extensions?
8. Which of the following is a clue that a virtual machine has been installed on a host
system?
9. To find network adapters, you use the ________ command in Windows and the
_______________ command in Linux.
10. What are the three modes of protection in the DiD strategy?
11. A layered network defense strategy puts the most valuable data where?
12. Tcpslice can be used to retrieve specific timeframes of packet captures. True or
False?
13. Packet analyzers examine what layers of the OSI model?