Questions
Answer the following questions to test your knowledge of this chapter:
- Named pipes are also known as _____ in Unix-like systems.
- An ASCII character is always 8 bits long, whereas a WCHAR character is always 16 bits long. (True | False)
- What does WMI stand for?
- What does IPC stand for?
- In addition to a returned error code, a successful remote WMI process call will also return the _____, which you can then use to verify your agent’s context.
- Shadow copies are copies of what?
- What’s the crucial piece of information contained in the
SYSTEM
hive for extracting hashes from the NTDS database?