1. Types of volatile information that can be recovered during a live response are:
|
Command history |
||
|
Process memory |
||
|
Cloud storage |
||
|
Jump lists |
||
|
Network connections |
2. Mike informs you that he visited one website, then immediately thereafter was put onto an entirely different website. What HTTP response is most likely?
|
500 HTTP Response |
||
|
100 HTTP Response |
||
|
300 HTTP Response |
||
|
400 HTTP Response |
3. Android and iOS devices store app data in _________ format. This evidence can be viewed with the Firefox SQL Developer add-on.
4. Why are Property list (plist) important to a forensic examiner when analyzing a Mac device?
5. Identify the full path to the file that will display the deleted users of the Mac computer. What evidentiary value can be found there?
1.
2.
3.
4.
Friend, this was a really nice question to answer. As per the Chegg policy, I am obliged to answer the first four questions. If you find my answer helpful, please like it. Thanks.
1. Types of volatile information that can be recovered during a live response are: Command history...