nerdexam
EC-Council

212-89 · Question #154

Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?

The correct answer is A. Autopsy. Autopsy is a digital forensics platform and graphical interface to The Sleuth Kit and other digital forensics tools. It is used by law enforcement, military, and corporate examiners to investigate what happened on a computer. Autopsy enables incident handlers to view the file…

Computer Forensics in Incident Handling

Question

Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?

Options

  • AAutopsy
  • Bnetstat
  • CProcess Explorer
  • Dnblslal

How the community answered

(43 responses)
  • A
    88% (38)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (3)

Explanation

Autopsy is a digital forensics platform and graphical interface to The Sleuth Kit and other digital forensics tools. It is used by law enforcement, military, and corporate examiners to investigate what happened on a computer. Autopsy enables incident handlers to view the file system, retrieve deleted data, perform timeline analysis, and analyze web artifacts, among other functionalities. This tool is particularly useful during the incident response process for conducting in-depth investigations into the nature of a security incident, identifying the methods used by attackers, and recovering lost or compromised data.

Topics

#digital forensics tools#Autopsy#file system analysis#deleted data recovery

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice