Exam Name: | Computer Hacking Forensic Investigator (v9) | ||
Exam Code: | 312-49v9 Dumps | ||
Vendor: | ECCouncil | Certification: | CHFIv9 |
Questions: | 589 Q&A's | Shared By: | malachi |
What system details can an investigator obtain from the NetBIOS name table cache?
Event correlation is the process of finding relevance between the events that produce a final result. What type of correlation will help an organization to correlate events across a set of servers, systems, routers and network?
NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is not a part of DDF?