ECCouncil Computer Hacking Forensic Investigator (CHFI-v10) 312-49v10 Question # 64 Topic 7 Discussion

ECCouncil Computer Hacking Forensic Investigator (CHFI-v10) 312-49v10 Question # 64 Topic 7 Discussion

312-49v10 Exam Topic 7 Question 64 Discussion:
Question #: 64
Topic #: 7

Which of the following tools will allow a forensic Investigator to acquire the memory dump of a suspect machine so that It may be Investigated on a forensic workstation to collect evidentiary data like processes and Tor browser artifacts?


A.

DB Browser SQLite


B.

Bulk Extractor


C.

Belkasoft Live RAM Capturer and AccessData FTK imager


D.

Hex Editor


Get Premium 312-49v10 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.