312-49 Exam Question 251

Which of the following file contains the traces of the applications installed, run, or uninstalled from a system?
  • 312-49 Exam Question 252

    John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?
  • 312-49 Exam Question 253

    When marking evidence that has been collected with the aa/ddmmyy/nnnn/zz format, what does the nnn denote?
  • 312-49 Exam Question 254

    Sniffers that place NICs in promiscuous mode work at what layer of the OSI model?
  • 312-49 Exam Question 255

    What does ICMP Type 3/Code 13 mean?