EC-Council: Computer Hacking Forensic Investigator(CHFI-V10)
Module 3 : Understanding Hard Disks and File Systems
         
Questions available : 89 You are not logged in.
Please Login for track your learning progress
   
 
Q. No: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 |
Go to Question No.



Question No 0


If you want to share the link of this question, please click here to "Copy Question Link" and share that generated link. Link from URL may change in future.
 

   
Bookmark this Question
QID: 164  
   
You are a forensic investigator who is analyzing a hard drive that was recently collected as evidence. You have been unsuccessful at locating any meaningful evidence within the file system and suspect a drive wiping utility may have been used. You have reviewed the keys within the software hive of the Windows registry and did not find any drive wiping utilities. How can you verify that drive wiping software was used on the hard drive?


 
A:    Check the list of installed programs
 
B:    Look for distinct repeating patterns on the hard drive at the bit level
C:    Document in your report that you suspect a drive wiping utility was used, but no evidence was found
 
D:    Load various drive wiping utilities offline, and export previous run reports
 
         

 
 

Diffence opinion in Correct Answer or any comment?
Vote / Comment for correct Answer




















WELCOME TO ONLINE EXAM PREPARATION SYSTEM

Certification Examinations