312-49v11 Exam Question 341
What file structure database would you expect to find on floppy disks?
312-49v11 Exam Question 342
An investigator is studying a suspicious Windows service discovered on a corporate system that seems to be associated with malware. The service has a name similar to a genuine Windows service, runs as a SYSTEM account, and exhibits potentially harmful behavior. Which tool and method should the investigator use to study the service's behavior without allowing it to inflict more damage?
312-49v11 Exam Question 343
Which of the following Windows event logs record events related to device drives and hardware changes?
312-49v11 Exam Question 344
When discussing the chain of custody in an investigation, what does a link refer to?
312-49v11 Exam Question 345
All Blackberry email is eventually sent and received through what proprietary RIM-operated mechanism?
