ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 13 - ECSS discussion

Report
Export

Which of the following MAC forensic data components saves file information and related events using a token with a binary structure?

A.

Kexts

Answers
A.

Kexts

B.

User account

Answers
B.

User account

C.

Command-line inputs

Answers
C.

Command-line inputs

D.

Basic Security Module

Answers
D.

Basic Security Module

Suggested answer: D

Explanation:

In the context of MAC (Mandatory Access Control) forensics, the Basic Security Module (BSM) is known to save file information and related events using a token with a binary structure. BSM is part of the auditing system that records security-related events and data. Each BSM audit record is composed of one or more tokens, where each token has a specific type identifier followed by data relevant to that token type. This structure allows for a detailed and organized way to store and retrieve event data, which is crucial for forensic analysis.

asked 24/10/2024
Michael White
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first