nerdexam
EC-Council

312-49 · Question #496

An executive has leaked the company trade secrets through an external drive. What process should the investigation team take if they could retrieve his system?

The correct answer is A. Postmortem Analysis. Postmortem Analysis (also called dead analysis or static analysis) is performed on a system after the incident has occurred - the system is no longer in its live, running state at the time of the leak. Since the investigators are retrieving the system after the fact, they…

Submitted by chiamaka_o· Apr 18, 2026Computer Forensics Investigation Process

Question

An executive has leaked the company trade secrets through an external drive. What process should the investigation team take if they could retrieve his system?

Options

  • APostmortem Analysis
  • BReal-Time Analysis
  • CPacket Analysis
  • DMalware Analysis

How the community answered

(35 responses)
  • A
    89% (31)
  • B
    6% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Postmortem Analysis (also called dead analysis or static analysis) is performed on a system after the incident has occurred - the system is no longer in its live, running state at the time of the leak. Since the investigators are retrieving the system after the fact, they analyze stored artifacts such as event logs, file system metadata, USB connection history, and registry entries to reconstruct what happened. Real-Time Analysis applies to live, running systems. Packet Analysis focuses on network traffic. Malware Analysis examines malicious software - none of which are the primary concern here.

Topics

#Postmortem Analysis#Incident Investigation#Data Leak#Forensic Methodology

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice