The forensic investigator uses this command to see what sessions are...
The investigator is looking to detect something after the incident has...
This displays all commands stored in memory.
The $l file contains all of the following EXCEPT:
The attorney that calls the witness to the stand is asking the...
Tanisha wants to recover files with their original file name....
This tool can be used to display details about GPT partition tables in...
Simple, sequential, flat files of a data set is called:
In this stage of the Linux boot process, information is retrieved from...
This approach monitors a computer and user's behavior for...
Johnny has been with the DEA for 17 years. He shows up on the...
The zz in exhibit numbering stands for:
The Master Boot Record (MBR) starts at this sector.
Shamika is the VP of Technology at XYZ, Inc. She suspects that...
An internal investigation, undertaken by an organization, to...
This type of analysis is ongoing and returns simultaneously, so that...
UTC stands for which of the following:
Misuse of a work computer generally can lead to this type of...
This law subsection covers child pornography.
This type of warrant is used to get records from service providers.
This type of attack is a combination of both a brute force attack and...
An investigator needs to jailbreak an iOS phone.
This file system uses journaling.
The attorney that called the witness to the stand is asking the...
This is the person initiating a lawsuit.
In a deposition, the following is true:
This is used to perform a Quick Analysis of a crash dump file.
These are bootloaders for Linux.
Object Linking and Embedding is not used by:
How can you find scheduled and unscheduled tasks on the local host?
This Federal statute covers child pornography
This person provides legal advice about the investigation and any...
GIF has how many bits per pixel
In FAT, the first letter of the deleted file name is replaced with:
Tasha is looking for the UEFI phase that involves clearing UEFI from...
A computer forensics lab should have windows all around the perimeter.
This rule governs proceedings in the courts of the United States.
UTC stands for:
This does not use OLE.
You can detect Trojans with which of the following?
This is an IDS:
Google Drive Configuration files are stored at this path:
The installation of Google Drive Client Version in Windows 10 creates...
This extracts data contained from an internet traffic capture
David needs a tool that contains an ISO image. He knows that...
When a file is deleted in FAT, the first letter of the deleted...
The nbtstat command can be used for:
18 USC p1030 covers:
Sectors are how many bytes long.
A warrantless seizure of digital evidence is used when:
A deposition is different from a regular trial in that:
How many bits per pixel does GIF contain?
Google Drive logs are:
Cisco shows this: %SEC-6-IPACCESSLOGP
MIME stream is found:
The first file system developed for Linux in 1992 was:
POP3 is used for:
Which of the following is not a benefit of cloud computing?
This Android library is used to render 2D (SGL) or 3D (OpenGL/ES)...
An investigator should use ______ imaging for copying data.
Poor controls around passwords and accounts in general would be...
This verifies the file system integrity of a volume, fixes logical...
This contains the manufacturer's information
These are saved in the installation folder in the user profile for...
This tool restores deleted emails and email attachments
Paco needs to open an Android phone. He should use:
This tool can be used to restore emails
POP3 runs on port:
For a router, the investigator should:
Which Windows version boots in either UEFI-GPT or BIOS-MBR?
Keira is an investigator with the FBI that needs to recover lost files...
What does ETI stand for?
A report, presented orally, to a board of directors, jury, or managers...
18 USC p 2252A covers
This is a sequence of bytes, organized into blocks understandable by...
BigCHFIDog.com is an e-Commerce business with $500,000 in annual...
SMTP normally runs on this port:
This is the starting point of a database.
Johnny has been caught with child porn. This investigation would...
Which of the following is true regarding digital evidence?
This tool can recover all types of lost files from disk or removable...
When a FAT file is deleted, what is placed at the front?
A deleted file in the Recycle Bin is named RIYH6VR.doc. This tells us:
Dropbox Client path:
This tool displays details about GPT partition tables in Mac OS
David needs to recover lost files from a USB flash drive. Which...
In Windows Server 2012 (IIS), log files are stored at:
Circular, metal disks mounted into the drive enclosure are called:
This is wasted area of the disk cluster, lying between the end of the...
A Digital Forensic Investigator investigates this type of crime...
This RAID level uses byte-level data striping across multiple drives...
A warrantless seizure can be used when
This event correlation approach monitors computer and user behavior...
Stacey needs to crack a Windows password. She can use which tool...
The Superblock in UFS has:
The attacker uses exploits to access other directories. This is...
This requires financial institutions to protect their customers'...
Scientific testimony.
Tools designated as software tools include all of the following...
The Daubert standard pertains to:
Registry Editor
Nasir is needing to recover lost data from RAID. He knows that this...
John wants to root an Apple phone. Which tool should he use?
Bob arrives on the scene of a large corporation after an...
Tracked user activities can be found in this file:
CAN-SPAM requires senders to honor opt-out requests within:
John is a forensic investigator working on a case for a WHC...
This is used to render 2D (SGL) or 3D graphics to the screen.
This can do data acquisition and duplication.
A small law firm suspects an incident, where there was potential...
All investigators keep track of the evidence path by using the:
All of the following are Android rooting tools EXCEPT
A first responder secures the scene perimeter. This is:
This is part of Metasploit that can be used to hide data in the slack...
David is looking for a tool that contains an ISO image, so he can burn...
This can be used to dump password hashes from the SAM file.
Which command can be used to look for suspicious connections and the...
UTC stands for:
System time is an example of non-volatile data.
This Tasklist command is used to run the command with the account...
This mobile API provides telephony services, like making calls,...
Mila wants to boot with either BIOS-MBR or UEFI-GPT. Which...
RAPID IMAGE 7020 X2 is designed to copy how many "Master" hard drives?
Jv16 can be used for
James enjoys this tool that offers thumbnail previews
Rule 1003 covers:
Phil is a digital forensic investigator that needs to obtain...
The FBI is investigating Sally for hacking her school's...
This is the smallest physical storage unit on the hard...
This is the Amendment that protects again unlawful search and seizure.
Rob wants to discover potential hidden information in an image...
This command can be used to see the names of all open shared files and...
This file is found at...
In exhibit numbering, the zz is for:
Which is not a file system?
This standard defines the use for file systems of CD-ROM and DVD...
This can be used for Last access time change in Windows 10.
Jamie is analyzing malware, but not executing it on his...
CD-ROM/DVD standard.
An attacker is using every possible combination of characters to crack...
ETI allows the investigator to:
Jv16 tool is used for
This tool is used to open registry hives
The insider threat caused a lot of chaos. Sally, the digital...
Sara is investigating an incident and needs to display information...
These determine the sector addressing for individual sectors on a...
This tool can be used to restore emails.
The img_stat command:
Which of the following is a starting hex value of an image file:
This contains the configuration information related to the user...
In FHS, essential user command binaries are in this.
Jonathan is an investigator, but he is not the first one on the...
This is a tool used for monitoring log files, produced by UNIX...
Intel is to EFI as PowerPC is to:
This can be used to detect Trojans.
Used for registry and not malware installation file analysis.
What is not one of the MS Exchange archive data files?
Opposing attorney, that did not call the witness to the stand, is...
Stacey wants to obtain data from social media websites. Which...
You can use this to see the last access time change for win10
You can view DBX files in:
This has journaling:
Sally is an investigator working for Diamond Corp. She needs to...
Roberta suspects the company's network has been compromised. How...
Sara is an Assistant U.S. Attorney. She knows that this rule...
All of the following are Registry tools EXCEPT:
Internal server error is error code:
This saves data about programs, so programs load faster at boot:
David has been called to the stand to offer scientific...
Julie wants to use an open-source format. What should she...
In Windows 7, deleted files are named $Ry.ext, where the y stands for...
Lenny needs to reset an Administrator password in order to access a...
Show active network connections with this:
This requires Federal agencies to develop, document, and implement...
A boot from restarting the OS is considered:
Data rescue 4 is:
Tools involved in Hashing include all of the following EXCEPT:
Which wondows version can use uefi-gpt or bios-mbr
Jamie needs a tool that can recover files with their original file...
This tool can be used to recover lost data from RAID and hard drives:
William needs a tool that can allow him to specify a specific file...
Which of the following is known for providing quick and deep scanning?
This command can be used to obtain details about partitions.
Richard wants to look for unusual network services. What command...
The max single file size in EXT3 is
Windows Event Log text file output format is:
The IMEI is obtained with:
$Bitmap is in:
In ISO 9660, what two file systems add more descriptors to the...
Which one do you like?
A hacker commits a DDoS attack against a specific IP address of a...
What file type is this? FF D8 FF E1
The first __ bits of the ESN is the manufacturer's code
Which one do you like?Max has arrived on scene and sees that the...
This is a tool for Mac OS
In Windows 98 and earlier, deleted files are named in Dxy.ext...
Jason is an investigator with over 10 years of experience. He...
Sara wants to perform a deep scan that scans the entire system. ...
HFS+ uses:
The GUID has this number of hexadecimal digits, with groups separated...