312-49v11 Exam Question 341

What file structure database would you expect to find on floppy disks?
  • 312-49v11 Exam Question 342

    An investigator is studying a suspicious Windows service discovered on a corporate system that seems to be associated with malware. The service has a name similar to a genuine Windows service, runs as a SYSTEM account, and exhibits potentially harmful behavior. Which tool and method should the investigator use to study the service's behavior without allowing it to inflict more damage?
  • 312-49v11 Exam Question 343

    Which of the following Windows event logs record events related to device drives and hardware changes?
  • 312-49v11 Exam Question 344

    When discussing the chain of custody in an investigation, what does a link refer to?
  • 312-49v11 Exam Question 345

    All Blackberry email is eventually sent and received through what proprietary RIM-operated mechanism?