nerdexam
EC-Council

312-49 · Question #540

Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB file and found the sour

Sign in or unlock 312-49 to reveal the answer and full explanation for question #540. The question stem and answer options stay visible for context.

Submitted by skyler.x· Apr 18, 2026Computer Forensics Investigation Process

Question

Adam, a forensic investigator, is investigating an attack on Microsoft Exchange Server of a large organization. As the first step of the investigation, he examined the PRIV.EDB file and found the source from where the mail originated and the name of the file that disappeared upon execution. Now, he wants to examine the MIME stream content. Which of the following files is he going to examine?

Options

  • APRIV.STM
  • Bgwcheck.db
  • CPRIV.EDB
  • DPUB.EDB

Unlock 312-49 to see the answer

You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Microsoft Exchange Server#Email Forensics#MIME Stream#PRIV.STM
Full 312-49 Practice