ECCouncil Computer Hacking Forensic Investigator (CHFI-v10) 312-49v10 Question # 88 Topic 9 Discussion

ECCouncil Computer Hacking Forensic Investigator (CHFI-v10) 312-49v10 Question # 88 Topic 9 Discussion

312-49v10 Exam Topic 9 Question 88 Discussion:
Question #: 88
Topic #: 9

You are a forensic investigator who is analyzing a hard drive that was recently collected as evidence. You have been unsuccessful at locating any meaningful evidence within the file system and suspect a drive wiping utility may have been used. You have reviewed the keys within the software hive of the Windows registry and did not find any drive wiping utilities. How can you verify that drive wiping software was used on the hard drive?


A.

Document in your report that you suspect a drive wiping utility was used, but no evidence was found


B.

Check the list of installed programs


C.

Load various drive wiping utilities offline, and export previous run reports


D.

Look for distinct repeating patterns on the hard drive at the bit level


Get Premium 312-49v10 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.