nerdexam
GIAC

GCFA · Question #258

Adam works as a professional Computer Hacking Forensic Investigator, a project has been assigned to him to investigate and examine files present on suspect's computer. Adam uses a tool with the help o

The correct answer is C. WinHex. WinHex is a professional forensic hex editor capable of examining deleted files, corrupted data, network captures, physical RAM, and virtual memory processes.

Advanced Incident Response & Digital Forensics Fundamentals

Question

Adam works as a professional Computer Hacking Forensic Investigator, a project has been assigned to him to investigate and examine files present on suspect's computer. Adam uses a tool with the help of which he can examine recovered deleted files, fragmented files, and other corrupted data. He can also examine the data, which was captured from the network, and access the physical RAM, and any processes running in virtual memory with the help of this tool. Which of the following tools is Adam using?

Options

  • AEvidor
  • BHxD
  • CWinHex
  • DVedit

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    7% (2)
  • C
    75% (21)
  • D
    4% (1)

Why each option

WinHex is a professional forensic hex editor capable of examining deleted files, corrupted data, network captures, physical RAM, and virtual memory processes.

AEvidor

Evidor is designed specifically to extract textual evidence and artifacts from Windows systems but does not provide the broad RAM, virtual memory, and raw disk forensic capabilities described.

BHxD

HxD is a free hex editor suitable for basic disk and memory editing but lacks the advanced forensic analysis features such as virtual memory process inspection described in the question.

CWinHexCorrect

WinHex is a universal hex editor and disk editor widely used in computer forensics. It supports examination of recovered deleted files, fragmented and corrupted data, network-captured data, physical RAM imaging, and inspection of processes in virtual memory - matching every capability described in the scenario.

DVedit

Vedit is a text and hex editing tool oriented toward programmers and does not provide the forensic-grade capabilities for analyzing deleted files, RAM, or network captures described in the scenario.

Concept tested: Computer forensics hex editor tool capabilities

Source: https://www.x-ways.net/winhex/

Topics

#WinHex#hex editor#forensic tools#deleted file recovery

Community Discussion

No community discussion yet for this question.

Full GCFA Practice