Exam 6: Current Computer Forensics Tools
Exam 1: Understanding the Digital Forensics Profession and Investigations50 Questions
Exam 2: The Investigators Office and Laboratory50 Questions
Exam 3: Data Acquisition50 Questions
Exam 4: Processing Crime and Incident Scenes50 Questions
Exam 5: Working With Windows and Cli Systems50 Questions
Exam 6: Current Computer Forensics Tools50 Questions
Exam 7: Macintosh and Linux Boot Processes and File Systems48 Questions
Exam 8: Recovering Graphics Files49 Questions
Exam 9: Computer Forensics Analysis and Validation50 Questions
Exam 10: Virtual Machine and Cloud Forensics50 Questions
Exam 11: Live Acquisitions and Network Forensics50 Questions
Exam 12: Email Investigations50 Questions
Exam 13: Cell Phone and Mobile Device Forensics49 Questions
Exam 14: Report Writing for High Tech Investigations50 Questions
Exam 15: Expert Testimony in High Tech Investigations50 Questions
Exam 16: Ethics for the Investigator and Expert Witness50 Questions
Select questions type
In general, forensics workstations can be divided into what categories? Explain each category.
(Essay)
4.9/5
(45)
Physically copying the entire drive is the only type of data-copying method used in software acquisitions.
(True/False)
4.7/5
(31)
What is the purpose of the reconstruction function in a forensics investigation?
(Multiple Choice)
4.8/5
(36)
The ProDiscover utility makes use of the proprietary _______________ file format.
(Multiple Choice)
4.8/5
(40)
The National Software Reference Library has compiled a list of known ___________ for a variety of OSs, applications, and images.
(Short Answer)
4.7/5
(29)
When performing disk acquisition, the raw data format is typically created with the UNIX/ Linux _____________ command.
(Multiple Choice)
4.9/5
(36)
What are the three minimum steps of a basic digital forensics examination protocol?
(Essay)
5.0/5
(43)
The __________ Linux Live CD includes tools such as Autopsy and Sleuth Kit, ophcrack, dcfldd, MemFetch, and MBoxGrep, and utilizes a KDE interface.
(Multiple Choice)
4.9/5
(38)
The physical data copy subfunction exists under the ______________ function.
(Multiple Choice)
4.7/5
(39)
The NIST ________________ program establishes guidelines for selecting and using forensics tools.
(Short Answer)
4.9/5
(37)
Showing 41 - 50 of 50
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)