312-49v10 Exam Question 31

Brian needs to acquire data from RAID storage. Which of the following acquisition methods is recommended to retrieve only the data relevant to the investigation?
  • 312-49v10 Exam Question 32

    Which of the following Registry components include offsets to other cells as well as the LastWrite time for the key?
  • 312-49v10 Exam Question 33

    ______allows a forensic investigator to identify the missing links during investigation.
  • 312-49v10 Exam Question 34

    A honey pot deployed with the IP 172.16.1.108 was compromised by an attacker. Given below is an excerpt from a Snort binary capture of the attack. Decipher the activity carried out by the attacker by studying the log. Please note that you are required to infer only what is explicit in the excerpt.
    (Note: The student is being tested on concepts learnt during passive OS fingerprinting, basic TCP/IP connection concepts and the ability to read packet signatures from a sniff dump.)
    03/15-20:21:24.107053 211.185.125.124:3500 -> 172.16.1.108:111
    TCP TTL:43 TOS:0x0 ID:29726 IpLen:20 DgmLen:52 DF
    ***A**** Seq: 0x9B6338C5 Ack: 0x5820ADD0 Win: 0x7D78 TcpLen: 32
    TCP Options (3) => NOP NOP TS: 23678634 2878772
    =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
    03/15-20:21:24.452051 211.185.125.124:789 -> 172.16.1.103:111
    UDP TTL:43 TOS:0x0 ID:29733 IpLen:20 DgmLen:84
    Len: 64
    01 0A 8A 0A 00 00 00 00 00 00 00 02 00 01 86 A0 ................
    00 00 00 02 00 00 00 03 00 00 00 00 00 00 00 00 ................
    00 00 00 00 00 00 00 00 00 01 86 B8 00 00 00 01 ................
    00 00 00 11 00 00 00 00 ........
    =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
    03/15-20:21:24.730436 211.185.125.124:790 -> 172.16.1.103:32773
    UDP TTL:43 TOS:0x0 ID:29781 IpLen:20 DgmLen:1104
    Len: 1084
    47 F7 9F 63 00 00 00 00 00 00 00 02 00 01 86 B8
  • 312-49v10 Exam Question 35

    This is original file structure database that Microsoft originally designed for floppy disks. It is written to the outermost track of a disk and contains information about each file stored on the drive.