nerdexam
EC-CouncilEC-Council

312-49 · Question #113

312-49 Question #113: Real Exam Question with Answer & Explanation

Sign in or unlock 312-49 to reveal the answer and full explanation for question #113. The question stem and answer options stay visible for context.

Submitted by hassan_iq· Apr 18, 2026Computer Forensics Investigation Process

Question

When collecting evidence from the RAM, where do you look for data?

Options

  • ASwap file
  • BSAM file
  • CData file
  • DLog file

Unlock 312-49 to see the answer

You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Memory Forensics#RAM Acquisition#Volatile Data#Swap File
Full 312-49 PracticeBrowse All 312-49 Questions