ECCouncil 312-49v10 Practice Test - Questions Answers, Page 52

List of questions
Question 511

What is an investigator looking for in the rp.log file stored in a system running on Windows 10 operating system?
Question 512

Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive. Which of the following statements is correct while dealing with local archives?
Question 513

Which of the following tool is used to locate IP addresses?
Question 514

Which of the following protocols allows non-ASCII files, such as video, graphics, and audio, to be sent through the email messages?
Question 515

What is the framework used for application development for iOS-based mobile devices?
Question 516

Chong-lee, a forensics executive, suspects that a malware is continuously making copies of files and folders on a victim system to consume the available disk space. What type of test would confirm his claim?
Question 517

Which of the following tools is not a data acquisition hardware tool?
Question 518

The given image displays information about date and time of installation of the OS along with service packs, patches, and sub-directories. What command or tool did the investigator use to view this output?
Question 519

Which list contains the most recent actions performed by a Windows User?
Question 520

Joshua is analyzing an MSSQL database for finding the attack evidence and other details, where should he look for the database logs?
Question