312-49 · Question #569
Which tool does the investigator use to extract artifacts left by Google Drive on the system?
The correct answer is C. RAM Capturer. RAM Capturer (such as Belkasoft RAM Capturer) acquires a full dump of volatile memory (RAM), which can contain live artifacts from running cloud-sync applications like Google Drive - including authentication tokens, cached file metadata, sync logs, and user activity not yet…
Question
Which tool does the investigator use to extract artifacts left by Google Drive on the system?
Options
- APEBrowse Professional
- BRegScanner
- CRAM Capturer
- DDependency Walker
How the community answered
(46 responses)- A2% (1)
- B2% (1)
- C89% (41)
- D7% (3)
Explanation
RAM Capturer (such as Belkasoft RAM Capturer) acquires a full dump of volatile memory (RAM), which can contain live artifacts from running cloud-sync applications like Google Drive - including authentication tokens, cached file metadata, sync logs, and user activity not yet written to disk. PEBrowse Professional and Dependency Walker are PE file analysis tools, and RegScanner is a registry scanning utility; none are designed to capture volatile memory artifacts from live cloud-sync processes.
Topics
Community Discussion
No community discussion yet for this question.