EC-CouncilEC-Council
312-49 · Question #113
312-49 Question #113: Real Exam Question with Answer & Explanation
Sign in or unlock 312-49 to reveal the answer and full explanation for question #113. The question stem and answer options stay visible for context.
Submitted by hassan_iq· Apr 18, 2026Computer Forensics Investigation Process
Question
When collecting evidence from the RAM, where do you look for data?
Options
- ASwap file
- BSAM file
- CData file
- DLog file
Unlock 312-49 to see the answer
You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Memory Forensics#RAM Acquisition#Volatile Data#Swap File