Udemy Test 5 Flashcards
This tool restores deleted emails and email attachments.
Data Recovery Pro
Max has arrived on scene and sees that the computer is turned on. His first step should be to (choose the best answer):
Photograph the current computer state
Which Windows version can use UEFI-GPT or BIOS-MBR?
Win10
The investigator has performed a bit-by-bit copy of a drive. Now the investigator wants to look for unusual network services. What command should be used?
net start
This type of password attack uses a combination of dictionary and brute force techniques.
Syllable
This tool displays details about GPT partition tables in Mac OS.
Disk Utility
jv16 can be used for:
registry
James enjoys this tool that offers thumbnails previews.
DiskDigger
Jamie needs a tool that can recover files with their original file name.
StellarPhoenix
This tool can be used for dynamic malware analysis.
Install Watch
David is looking for a tool that contains an ISO image, so he can burn a bootable CD. What tool is he looking for?
Active@ File Recovery
This extracts data contained from an internet traffic capture.
Xplico
Samuel has completed static analysis of a new malware strain. He is now going to perform dynamic analysis. Which tool can he use to monitor for installations, while performing dynamic analysis?
SysAnalyzer
Paco needs to open an Android phone. He should use:
TowelRoot
Nasir is needing to recover lost data from RAID. He knows that this tool will be needed.
TotalRecall
Jennifer is an investigator with the FBI. She is performing dynamic analysis on malware and wants to know the dependencies. What tool should she use?
Dependency Walker
This can recover documents, even if Windows is reinstalled.
UndeletePlus
This tool recovers all file types from a HFS formatted drive.
Data Rescue 4
This is an open source NFAT.
Xplico
CAN-SPAM requires senders to honor opt-out requests within:
10 Business Days
PUB.EDB:
Stores public folder hierarchies and contents
RAPID IMAGE 7020 X2 is designed to copy how many “Master” hard drives?
one
This rule covers limited admissibility.
Rule 105
This can recover files from newly formatted drives.
Recuva