Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 788 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 788
Topic #: 1
[All 312-49v10 Questions]

A forensic investigator is analyzing a Windows system for possible malicious activity. The investigator is specifically interested in the recent actions of a suspect on the system, including any deleted directories or files, mounted drives, and actions taken. Which of the following approaches and tools would be the most effective for obtaining this information?

  • A. Analyzing LNK files using ShellBags Explorer
  • B. Investigating Jump Usts using ShellBagsView
  • C. Parsing the BagMRU and Bags registry keys using SBag
  • D. Examining the MRUListEx key and NodeSlot value in Windows Explorer
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
4bd3116
4 months ago
Selected Answer: C
C. Parsing the BagMRU and Bags registry keys using SBag This approach is the most effective for obtaining detailed information about recent actions, deleted directories, and mounted drives. It leverages the ShellBags data stored in the Windows registry, which includes valuable historical information about user interactions with the filesystem.
upvoted 1 times
...
aqeel1506
4 months ago
C: Parsing the BagMRU and Bags registry keys using SBag: This option aligns well with the CHFI v10 textbook’s emphasis on examining ShellBag data, which includes the BagMRU and Bags registry keys. SBag is designed to parse ShellBag information, making it an effective tool for analyzing accessed and deleted directories.
upvoted 2 times
...
Elb
5 months, 2 weeks ago
LNK is a file extension for shortcut files used by Windows OS to point to any executable files These files are created when a user/suspect accesses any local/remote file and can provide forensic investigator with valuable information on user activities on the system These artifacts also help forensic investigators find the LNK files associated with the original files that no longer exists on the target machine
upvoted 1 times
...
Elb
5 months, 2 weeks ago
The ShellBags contain information pertaining to the directories (accessed by the user) even after the directory is removed, which can be used to enumerate previously mounted drives, deleted files and User/Intruder action.
upvoted 1 times
...
Elb
5 months, 2 weeks ago
Analyzing ShellBags provides forensic investigators with data such as: ▪ Folders opened by user from a mounted external hard drive.
upvoted 1 times
...
Elb
5 months, 4 weeks ago
Selected Answer: A
ShellBags are a set of registry keys which record the viewing preferences of folders of the user, such as their size, location and position, when using Windows Explorer. The information in these ShellBags plays a crucial role in the forensic investigation as it provides evidence related to folders accessed by a user.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...