Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 643 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 643
Topic #: 1
[All 312-49v10 Questions]

Which following forensic tool allows investigator to detect and extract hidden streams on NTFS drive?

  • A. Autopsy
  • B. TimeStomp
  • C. analyzeMFT
  • D. Stream Detector
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Elb
6 months ago
Selected Answer: D
Stream Detector is a forensic tool that identifies all hidden files such as images, videos, text, and executables within Alternate Data Streams present on NTFS drives It can detect the hidden streams on actual file directory and lists hidden stream file name, stream type, size of the stream, etc. This tool can be used to detect and extract hidden streams, delete the file and unwanted streams.
upvoted 1 times
...
Elb
7 months, 1 week ago
Selected Answer: D
https://www.appsvoid.com/products/stream-detector/
upvoted 1 times
...
Elb
7 months, 1 week ago
D < https://www.appsvoid.com/products/stream-detector/ "This tool can be used to find and delete hidden alternate data streams used by malware and rootkits, such...."
upvoted 1 times
...
581777a
1 year, 3 months ago
Selected Answer: C
C. analyzeMFT The forensic tool "analyzeMFT" allows investigators to detect and extract hidden streams on NTFS (New Technology File System) drives. Hidden streams are a feature of NTFS that allows data to be associated with a file without being immediately visible in the regular file system. Analyzing the Master File Table (MFT) can reveal information about these hidden streams and their associated files. Option A (Autopsy) is an open-source digital forensics platform primarily used for analyzing disk images and file systems. Option B (TimeStomp) is a tool used to manipulate file timestamps, not specifically for detecting hidden streams. Option D ("Stream Detector") is not a recognized tool in the context of forensic analysis.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...