nerdexam
GIAC

GCFE · Question #30

During a forensic investigation, you need to determine if a user intentionally deleted files to hide evidence. Which artifacts would you analyze to confirm this? (Choose three)

The correct answer is A. Recycle Bin D. File metadata E. RecentDocs registry key. See the full explanation below for the reasoning.

Question

During a forensic investigation, you need to determine if a user intentionally deleted files to hide evidence. Which artifacts would you analyze to confirm this? (Choose three)

Options

  • ARecycle Bin
  • BPrefetch files
  • CNTUSER.DAT
  • DFile metadata
  • ERecentDocs registry key

How the community answered

(31 responses)
  • A
    77% (24)
  • B
    16% (5)
  • C
    6% (2)

Community Discussion

No community discussion yet for this question.

Full GCFE Practice