nerdexam
EC-Council

312-49 · Question #569

Which tool does the investigator use to extract artifacts left by Google Drive on the system?

The correct answer is C. RAM Capturer. RAM Capturer (such as Belkasoft RAM Capturer) acquires a full dump of volatile memory (RAM), which can contain live artifacts from running cloud-sync applications like Google Drive - including authentication tokens, cached file metadata, sync logs, and user activity not yet…

Submitted by andres_qro· Apr 18, 2026Cloud Forensics

Question

Which tool does the investigator use to extract artifacts left by Google Drive on the system?

Options

  • APEBrowse Professional
  • BRegScanner
  • CRAM Capturer
  • DDependency Walker

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    89% (41)
  • D
    7% (3)

Explanation

RAM Capturer (such as Belkasoft RAM Capturer) acquires a full dump of volatile memory (RAM), which can contain live artifacts from running cloud-sync applications like Google Drive - including authentication tokens, cached file metadata, sync logs, and user activity not yet written to disk. PEBrowse Professional and Dependency Walker are PE file analysis tools, and RegScanner is a registry scanning utility; none are designed to capture volatile memory artifacts from live cloud-sync processes.

Topics

#Cloud Forensics#Volatile Memory Acquisition#Digital Artifacts#Google Drive Forensics

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice