Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam 312-49v10 All Questions
Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

ECCouncil CHFI v10 312-49v10 Question # 147 Topic 16 Discussion

312-49v10 Exam Topic 16 Question 147 Discussion:
Question #: 147
Topic #: 16

Which of the following tools will allow a forensic Investigator to acquire the memory dump of a suspect machine so that It may be Investigated on a forensic workstation to collect evidentiary data like processes and Tor browser artifacts?


A.

DB Browser SQLite


B.

Bulk Extractor


C.

Belkasoft Live RAM Capturer and AccessData FTK imager


D.

Hex Editor


Get Premium 312-49v10 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.