ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 694 - 312-49v10 discussion

Report
Export

You are a forensic investigator who is analyzing a hard drive that was recently collected as evidence.

You have been unsuccessful at locating any meaningful evidence within the file system and suspect a drive wiping utility may have been used. You have reviewed the keys within the software hive of the Windows registry and did not find any drive wiping utilities. How can you verify that drive wiping software was used on the hard drive?

A.
Document in your report that you suspect a drive wiping utility was used, but no evidence was found
Answers
A.
Document in your report that you suspect a drive wiping utility was used, but no evidence was found
B.
Check the list of installed programs
Answers
B.
Check the list of installed programs
C.
Load various drive wiping utilities offline, and export previous run reports
Answers
C.
Load various drive wiping utilities offline, and export previous run reports
D.
Look for distinct repeating patterns on the hard drive at the bit level
Answers
D.
Look for distinct repeating patterns on the hard drive at the bit level
Suggested answer: D
asked 18/09/2024
Francesco Gallo
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first