- (Exam Topic 2)
In Windows Security Event Log, what does an event id of 530 imply?
Correct Answer:C
- (Exam Topic 1)
When conducting computer forensic analysis, you must guard against _______ So that you remain focused on the primary job and insure that the level of work does not increase beyond what was originally expected.
Correct Answer:B
- (Exam Topic 2)
Smith, a forensic examiner, was analyzing a hard disk image to find and acquire deleted sensitive files. He stumbled upon a $Recycle.Bin folder in the root directory of the disk. Identify the operating system in use.
Correct Answer:D
- (Exam Topic 1)
What does the acronym POST mean as it relates to a PC?
Correct Answer:B
- (Exam Topic 1)
Corporate investigations are typically easier than public investigations because:
Correct Answer:B
- (Exam Topic 3)
Brian needs to acquire data from RAID storage. Which of the following acquisition methods is recommended to retrieve only the data relevant to the investigation?
Correct Answer:B