Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 510 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 510
Topic #: 1
[All 312-49v10 Questions]

What is an investigator looking for in the rp.log file stored in a system running on Windows 10 operating system?

  • A. Restore point interval
  • B. Automatically created restore points
  • C. System CheckPoints required for restoring
  • D. Restore point functions
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Elb
6 months ago
Selected Answer: B
Automatically created restore points have names assigned to them that are stored in the file rp.log located in the root of the folder RP##
upvoted 1 times
...
Elb
7 months, 1 week ago
B< Restore points may contain the key piece of evidence to support a case, but are commonly overlooked. Content within restore points can be a crippling piece of history to leave behind for an attacker, exposing code, configurations and log files.
upvoted 1 times
...
Malko59
1 year, 3 months ago
Selected Answer: B
B is correct. - B: Restore point are created if software or unsigned drivers are installed. It can help investigator to identify some change on the system made by attacker. - C: System CheckPoints are created on schedule.
upvoted 2 times
...
diomaya
1 year, 5 months ago
Selected Answer: B
From EC-Council CHFI v10 book: Automatically created restore points have names assigned to them that are stored in the file rp.log located in the root of the folder RP##
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...