Exam Name: | Computer Hacking Forensic Investigator (CHFI-v10) | ||
Exam Code: | 312-49v10 Dumps | ||
Vendor: | ECCouncil | Certification: | CHFI v10 |
Questions: | 704 Q&A's | Shared By: | lochlan |
When investigating a computer forensics case where Microsoft Exchange and Blackberry Enterprise server are used, where would investigator need to search to find email sent from a Blackberry device?
Microsoft Security IDs are available in Windows Registry Editor. The path to locate IDs in Windows 7 is:
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?