- (Exam Topic 4)
"No action taken by law enforcement agencies or their agents should change data held on a computer or storage media which may subsequently be relied upon in court" - this principle Is advocated by which of the following?
Correct Answer:
A
- (Exam Topic 3)
In Linux OS, different log files hold different information, which help the investigators to analyze various
issues during a security incident. What information can the investigators obtain from the log file var/log/dmesg?
Correct Answer:
A
- (Exam Topic 3)
Rusty, a computer forensics apprentice, uses the command nbtstat –c while analyzing the network information in a suspect system. What information is he looking for?
Correct Answer:
C
- (Exam Topic 1)
The efforts to obtain information before a trail by demanding documents, depositions, questioned and answers written under oath, written requests for admissions of fact and examination of the scene is a description of what legal term?
Correct Answer:
D
- (Exam Topic 3)
What is the capacity of Recycle bin in a system running on Windows Vista?
Correct Answer:
C