ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 56 - ECSS discussion

Report
Export

James, a forensic specialist, was appointed to investigate an incident in an organization. As part of the investigation, James is attempting to identify whether any external storage devices are connected to the internal systems. For this purpose, he employed a utility to capture the list of all devices connected to the local machine and removed suspicious devices.

Identify the tool employed by James in the above scenario.

A.

Promise Detect

Answers
A.

Promise Detect

B.

DriveLetlerView

Answers
B.

DriveLetlerView

C.

ESEDatabaseView

Answers
C.

ESEDatabaseView

D.

ProcDump

Answers
D.

ProcDump

Suggested answer: B

Explanation:

In the given scenario, James employed theDriveLetterViewutility to capture the list of all devices connected to the local machine. DriveLetterView is a tool that displays a list of drive letters assigned to drives on a computer, including external storage devices.By using this utility, James can identify any suspicious devices connected to the internal systems.Reference: EC-Council Certified Security Specialist (E|CSS) documents and study guide12.

asked 24/10/2024
MICHELE CRISTINA DOS FELIX
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first