exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 114 discussion

Actual exam question from CompTIA's CAS-004
Question #: 114
Topic #: 1
[All CAS-004 Questions]

A forensic investigator would use the foremost command for:

  • A. cloning disks.
  • B. analyzing network-captured packets.
  • C. recovering lost files.
  • D. extracting features such as email addresses.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
beanbag
Highly Voted 1 year, 7 months ago
Selected Answer: C
Foremost is a forensic program to recover lost files based on their headers, footers, and internal data structures.
upvoted 7 times
...
Meep123
Most Recent 7 months ago
C "Foremost is a forensic program to recover lost files based on their headers, footers, and internal data structures." --https://www.kali.org/tools/foremost/#:~:text=Foremost%20is%20a%20forensic%20program%20to%20recover%20lost,Safeback%2C%20Encase%2C%20etc%2C%20or%20directly%20on%20a%20drive.
upvoted 2 times
...
BiteSize
9 months, 1 week ago
Selected Answer: C
Cloning disks = dd PCAP = Tcpdump Lost files = foremost Extracting features = grep Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 2 times
...
Mr_BuCk3th34D
1 year, 3 months ago
Selected Answer: C
Foremost is a command-line tool that can be used to recover lost files from a disk or other storage medium. It works by scanning the storage medium and identifying file headers and footers that match certain file types. It then extracts the data contained in those files and saves it to a specified location. Foremost is commonly used in forensic investigations to recover lost or deleted files that may contain evidence of a crime or other wrongdoing.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago