ECCouncil Computer Hacking Forensic Investigator 312-49 Question # 76 Topic 8 Discussion

ECCouncil Computer Hacking Forensic Investigator 312-49 Question # 76 Topic 8 Discussion

312-49 Exam Topic 8 Question 76 Discussion:
Question #: 76
Topic #: 8

In a forensic examination of hard drives for digital evidence, what type of user is most likely to have the most file slack to analyze?


A.

one who has NTFS 4 or 5 partitions


B.

one who uses dynamic swap file capability


C.

one who uses hard disk writes on IRQ 13 and 21


D.

one who has lots of allocation units per block or cluster


Get Premium 312-49 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.