ECCouncil 312-49v10 Practice Test - Questions Answers, Page 22
List of questions
Question 211
What type of equipment would a forensics investigator store in a StrongHold bag?
Question 212
If you are concerned about a high level of compression but not concerned about any possible data loss, what type of compression would you use?
Question 213
When marking evidence that has been collected with the aa/ddmmyy/nnnn/zz format, what does the nnn denote?
Question 214
An investigator is searching through the firewall logs of a company and notices ICMP packets that are larger than 65,536 bytes. What type of activity is the investigator seeing?
Question 215
When carrying out a forensics investigation, why should you never delete a partition on a dynamic disk?
Question 216
When using an iPod and the host computer is running Windows, what file system will be used?
Question 217
What is one method of bypassing a system BIOS password?
Question 218
What technique used by Encase makes it virtually impossible to tamper with evidence once it has been acquired?
Question 219
What must an investigator do before disconnecting an iPod from any type of computer?
Question 220
The following is a log file screenshot from a default installation of IIS 6.0.
What time standard is used by IIS as seen in the screenshot?
Question