EC-Council: Computer Hacking Forensic Investigator(CHFI-V10)
Module 3 : Understanding Hard Disks and File Systems
         
Questions available : 89 You are not logged in.
Please Login for track your learning progress
   
 
Q. No: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 |
Go to Question No.



Question No 0


If you want to share the link of this question, please click here to "Copy Question Link" and share that generated link. Link from URL may change in future.
 

   
Bookmark this Question
QID: 795  
   
In a forensic examination of hard drives for digital evidence, what type of user is most likely to have the most file slack to analyze?


 
A:    one who has NTFS 4 or 5 partitions
 
B:    one who uses dynamic swap file capability
C:    one who uses hard disk writes on IRQ 13 and 21
 
D:    one who has lots of allocation units per block or cluster
 
         

 
 

Diffence opinion in Correct Answer or any comment?
Vote / Comment for correct Answer




















WELCOME TO ONLINE EXAM PREPARATION SYSTEM

Certification Examinations