exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 717 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 717
Topic #: 1
[All 312-49v10 Questions]

A Computer Hacking Forensics Investigator (CHFI) has been asked to retrieve specific email files from a large RAID server after a data breach. Additionally, fragments of unallocated (deleted) data are also required. However, there is a severe constraint on time and resources. Considering these requirements, which type of data acquisition should the investigator primarily focus on?

  • A. Logical acquisition
  • B. Bit-stream disk-to-disk
  • C. Sparse acquisition
  • D. Bit-stream disk-to-image-file
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
044f354
1 month ago
Selected Answer: C
Answer: C Explanation: (A) ❌ Logical acquisition retrieves only active files, missing unallocated (deleted) data. (B) ❌ Bit-stream disk-to-disk is comprehensive but time/resource-intensive. (C) ✅ Sparse acquisition targets specific files and unallocated fragments, optimizing time/resources. (D) ❌ Bit-stream disk-to-image-file is thorough but inefficient under severe constraints. ----- If you agree, please UPVOTE. Each time you upvote someone with a yellow "SELECTED ANSWER: " banner (like me) your vote is added to the Community Vote Distribution, which helps the community by crowdsourcing correct answers.
upvoted 1 times
...
4bd3116
8 months, 4 weeks ago
Selected Answer: D
While logical acquisition is faster and can efficiently retrieve specific files, it does not capture deleted data. Given that the CHFI must retrieve both specific email files and fragments of unallocated data, bit-stream disk-to-image-file would be the more appropriate choice despite its higher time and resource requirements. This method ensures that all relevant data, including deleted fragments, is available for analysis
upvoted 1 times
...
aqeel1506
9 months ago
so the answer is A logical acquisition
upvoted 1 times
...
aqeel1506
9 months ago
Logical Acquisition is often recommended when the focus is on retrieving specific files or types of data, especially under time constraints. Sparse Acquisition is useful in some scenarios but may not be ideal for comprehensive retrieval of specific files and unallocated data, as it is more selective. Thus, Logical acquisition aligns with the CHFI textbook’s guidance on effectively addressing the need to quickly retrieve specific files and data fragments in a constrained environment.
upvoted 1 times
...
Elb
10 months, 2 weeks ago
Selected Answer: C
Sparse acquisition is similar to logical acquisition. Through this method, investigators can collect fragments of unallocated (deleted) data. This method is useful when it is not necessary to inspect the entire drive.
upvoted 3 times
...
Elb
12 months ago
C < https://info-savvy.com/data-acquisition-methods/#:~:text=2.-,Sparse%20Acquisition,to%20inspect%20the%20entire%20drive.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago