GCIA · Question #69
Adam works as a professional Computer Hacking Forensic Investigator. He has been assigned with a project to investigate a computer in the network of SecureEnet Inc. The compromised system runs on Wind
The correct answer is D. FSP. In Helix Live for Windows, the FSP (Forensic Server Project) is the specific component designed to capture volatile data from a live Windows system and transmit it to a remote server over TCP/IP.
Question
Adam works as a professional Computer Hacking Forensic Investigator. He has been assigned with a project to investigate a computer in the network of SecureEnet Inc. The compromised system runs on Windows operating system. Adam decides to use Helix Live for Windows to gather data and electronic evidences starting with retrieving volatile data and transferring it to server component via TCP/IP. Which of the following application software in Helix Windows Live will he use to retrieve volatile data and transfer it to the server component via TCP/IP?
Options
- AFAU
- BFTK imager
- CDrive Manager
- DFSP
How the community answered
(69 responses)- A3% (2)
- B16% (11)
- C7% (5)
- D74% (51)
Why each option
In Helix Live for Windows, the FSP (Forensic Server Project) is the specific component designed to capture volatile data from a live Windows system and transmit it to a remote server over TCP/IP.
FAU (File Access Utility) is used to access files on a live system without altering timestamps, not to transfer volatile data over TCP/IP.
FTK Imager is a disk imaging tool used to create forensic images of storage media, not to capture and transmit volatile system data over a network.
Drive Manager is used for managing and interacting with physical drives, not for live volatile data capture or TCP/IP-based transfer to a server.
FSP, or Forensic Server Project, is the Helix Live component that operates as a client-server tool allowing volatile data (such as running processes, network connections, and memory contents) to be streamed from the compromised system to a remote forensic server via TCP/IP. This design preserves the integrity of volatile evidence that would otherwise be lost on shutdown. It is specifically built for live acquisition over a network, distinguishing it from other Helix tools that operate locally or on disk images.
Concept tested: Helix Live volatile data acquisition via network
Topics
Community Discussion
No community discussion yet for this question.