List of questions
Related questions
Question 694 - 312-49v10 discussion
You are a forensic investigator who is analyzing a hard drive that was recently collected as evidence.
You have been unsuccessful at locating any meaningful evidence within the file system and suspect a drive wiping utility may have been used. You have reviewed the keys within the software hive of the Windows registry and did not find any drive wiping utilities. How can you verify that drive wiping software was used on the hard drive?
A.
Document in your report that you suspect a drive wiping utility was used, but no evidence was found
B.
Check the list of installed programs
C.
Load various drive wiping utilities offline, and export previous run reports
D.
Look for distinct repeating patterns on the hard drive at the bit level
Your answer:
0 comments
Sorted by
Leave a comment first