Question 26

A Linux system is undergoing investigation. In which directory should the investigators look for its current state data if the system is in powered on state?
  • Question 27

    Bob has encountered a system crash and has lost vital data stored on the hard drive of his Windows computer. He has no cloud storage or backup hard drives. He wants to recover all the data, which includes his personal photos, music, documents, videos, official emails, etc. Which of the following tools shall resolve Bob's purpose?
  • Question 28

    When examining a hard disk without a write-blocker, you should not start windows because Windows will write data to the:
  • Question 29

    Sheila is a forensics trainee and is searching for hidden image files on a hard disk. She used a forensic investigation tool to view the media in hexadecimal code for simplifying the search process. Which of the following hex codes should she look for to identify image files?
  • Question 30

    What is kept in the following directory? HKLM\SECURITY\Policy\Secrets