nerdexam
CompTIA

CAS-003 · Question #241

A forensic analyst receives a hard drive containing malware quarantined by the antivirus application. After creating an image and determining the directory location of the malware file, which of the…

The correct answer is B. The timeline analysis of the file system. Timelines can be used in digital forensics to identify when activity occurred on a computer. Timelines are mainly used for data reduction or identifying specific state changes that have occurred on a computer.

Enterprise Security Operations

Question

A forensic analyst receives a hard drive containing malware quarantined by the antivirus application. After creating an image and determining the directory location of the malware file, which of the following helps to determine when the system became infected?

Options

  • AThe malware file's modify, access, change time properties.
  • BThe timeline analysis of the file system.
  • CThe time stamp of the malware in the swap file.
  • DThe date/time stamp of the malware detection in the antivirus logs.

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    75% (21)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Timelines can be used in digital forensics to identify when activity occurred on a computer. Timelines are mainly used for data reduction or identifying specific state changes that have occurred on a computer.

Topics

#digital forensics#timeline analysis#file system metadata#malware investigation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice