nerdexam
GIAC

GCIA · Question #69

Adam works as a professional Computer Hacking Forensic Investigator. He has been assigned with a project to investigate a computer in the network of SecureEnet Inc. The compromised system runs on Wind

The correct answer is D. FSP. In Helix Live for Windows, the FSP (Forensic Server Project) is the specific component designed to capture volatile data from a live Windows system and transmit it to a remote server over TCP/IP.

Network Forensics, Protocol Insecurity & Evasion Techniques

Question

Adam works as a professional Computer Hacking Forensic Investigator. He has been assigned with a project to investigate a computer in the network of SecureEnet Inc. The compromised system runs on Windows operating system. Adam decides to use Helix Live for Windows to gather data and electronic evidences starting with retrieving volatile data and transferring it to server component via TCP/IP. Which of the following application software in Helix Windows Live will he use to retrieve volatile data and transfer it to the server component via TCP/IP?

Options

  • AFAU
  • BFTK imager
  • CDrive Manager
  • DFSP

How the community answered

(69 responses)
  • A
    3% (2)
  • B
    16% (11)
  • C
    7% (5)
  • D
    74% (51)

Why each option

In Helix Live for Windows, the FSP (Forensic Server Project) is the specific component designed to capture volatile data from a live Windows system and transmit it to a remote server over TCP/IP.

AFAU

FAU (File Access Utility) is used to access files on a live system without altering timestamps, not to transfer volatile data over TCP/IP.

BFTK imager

FTK Imager is a disk imaging tool used to create forensic images of storage media, not to capture and transmit volatile system data over a network.

CDrive Manager

Drive Manager is used for managing and interacting with physical drives, not for live volatile data capture or TCP/IP-based transfer to a server.

DFSPCorrect

FSP, or Forensic Server Project, is the Helix Live component that operates as a client-server tool allowing volatile data (such as running processes, network connections, and memory contents) to be streamed from the compromised system to a remote forensic server via TCP/IP. This design preserves the integrity of volatile evidence that would otherwise be lost on shutdown. It is specifically built for live acquisition over a network, distinguishing it from other Helix tools that operate locally or on disk images.

Concept tested: Helix Live volatile data acquisition via network

Topics

#Helix Live#volatile data collection#digital forensics#forensic tools

Community Discussion

No community discussion yet for this question.

Full GCIA Practice