ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 76 - ECSS discussion

Report
Export

Jack, a forensic investigator, was appointed to investigate a Windows-based security incident. In this process, he employed an Autopsy tool to recover the deleted files from unallocated space, which helps in gathering potential evidence.

Which of the following functions of Autopsy helped Jack recover the deleted files?

A.

Timeline analysis

Answers
A.

Timeline analysis

B.

Web artifacts

Answers
B.

Web artifacts

C.

Data carving

Answers
C.

Data carving

D.

Multimedia

Answers
D.

Multimedia

Suggested answer: C

Explanation:

Comprehensive Explanation: TheAutopsytool is a digital forensics platform that assists investigators in analyzing and recovering evidence from various sources. One of its crucial functions isdata carving. Here's how it works:

Data Carving:

Data carving, also known asfile carving, is a technique used to retrieve files from unallocated space on storage devices.

When files are deleted, they may not be immediately overwritten. Instead, their remnants remain in unallocated areas of the storage medium.

Autopsy'sPhotoRec Carver moduleperforms data carving by scanning unallocated space, identifying file signatures, and recovering deleted files.

These files are often found in seemingly ''empty'' portions of the device storage.

By analyzing unallocated space, Autopsy can uncover potential evidence that was previously deleted.

EC-Council Certified Security Specialist (E|CSS) documents and study guide.

Autopsy User Documentation:PhotoRec Carver Module

asked 24/10/2024
Enrique Villegas
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first