RAM Capture is a live data acquisition. Live data acquisition can help investigators obtain information even if the data of evidentiary value is stored on the cloud using a service such as Dropbox or Google Drive. Computer Hacking Forensics Investigator (CHFI) Version 10
EC-Council Pg. 349
This is probably B. RegScanner will let you search the registry for remaining artifacts. RAMCapturer lets you extract volatile memory and doesn't fit the question as well.
RAMCapturer can reveal sensitive data such as Username/Password used to login to the account.
Answer is right.
upvoted 6 times
...
...
This section is not available anymore. Please use the main Exam Page.312-49 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ceh2024
8 months, 1 week agofoolish
3 years, 6 months agoMarcoSenno
3 years, 3 months ago