312-49 Exam Question 251
Which of the following file contains the traces of the applications installed, run, or uninstalled from a system?
312-49 Exam Question 252
John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?
312-49 Exam Question 253
When marking evidence that has been collected with the aa/ddmmyy/nnnn/zz format, what does the nnn denote?
312-49 Exam Question 254
Sniffers that place NICs in promiscuous mode work at what layer of the OSI model?
312-49 Exam Question 255
What does ICMP Type 3/Code 13 mean?
