312-49v9 Exam Question 71

A small law firm located in the Midwest has possibly been breached by a computer hacker looking to obtain information on their clientele. The law firm does not have any on-site IT employees, but wants to search for evidence of the breach themselves to prevent any possible media attention. Why would this not be recommended?
  • 312-49v9 Exam Question 72

    Harold is a computer forensics investigator working for a consulting firm out of Atlanta
    Georgia. Harold is called upon to help with a corporate espionage case in Miami Florida.
    Harold assists in the investigation by pulling all the data from the computers allegedly used in the illegal activities. He finds that two suspects in the company where stealing sensitive corporate information and selling it to competing companies. From the email and instant messenger logs recovered, Harold has discovered that the two employees notified the buyers by writing symbols on the back of specific stop signs. This way, the buyers knew when and where to meet with the alleged suspects to buy the stolen material. What type of steganography did these two suspects use?
  • 312-49v9 Exam Question 73

    Which of the following standard represents a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?
  • 312-49v9 Exam Question 74

    Jason has set up a honeypot environment by creating a DMZ that has no physical or logical access to his production network. In this honeypot, he has placed a server running Windows Active Directory. He has also placed a Web server in the DMZ that services a number of web pages that offer visitors a chance to download sensitive information by clicking on a button. A week later, Jason finds in his network logs how an intruder accessed the honeypot and downloaded sensitive information. Jason uses the logs to try and prosecute the intruder for stealing sensitive corporate information. Why will this not be viable?
  • 312-49v9 Exam Question 75

    Which tool does the investigator use to extract artifacts left by Google Drive on the system?