The correct answer is B. RegScanner.
RegScanner is a tool used to extract artifacts from the Windows Registry, including those left by Google Drive. Google Drive stores its settings and metadata in the Registry, and RegScanner can help investigators extract this information.
Here's a brief explanation of the other options:
A. PEBrowse Professional: A tool used to analyze the Windows Process Environment Block (PEB) and extract information about running processes, not related to Google Drive artifacts.
C. RAM Capturer: A tool used to capture and analyze the contents of physical memory (RAM), not related to Google Drive artifacts.
D. Dependency Walker: A tool used to analyze the dependencies and libraries used by executable files, not related to Google Drive artifacts.
C > Belkasoft Live RAM Capturer is a forensic tool that allows extracting the entire contents of a computer’s volatile memory
https://www.forensicfocus.com/webinars/acquiring-removable-drives-mobile-devices-ram-and-cloud-storage/
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
4bd3116
4 months agoaqeel1506
4 months agoElb
6 months ago