exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 549 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 549
Topic #: 1
[All 312-49v10 Questions]

Consider that you are investigating a machine running an Windows OS released prior to Windows Vista. You are trying to gather information about the deleted files by examining the master database file named INFO2 located at C:\Recycler\<USER SID>\. You read an entry named "Dd5.exe". What does Dd5.exe mean?

  • A. D drive. fifth file deleted, a .exe file
  • B. D drive, fourth file restored, a .exe file
  • C. D drive, fourth file deleted, a .exe file
  • D. D drive, sixth file deleted, a .exe file
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Malko59
Highly Voted 1 year, 8 months ago
Selected Answer: A
A is correct (same issue as question 411) There is a mistake in the CHFI V10 book. In page 429 the example is wrong. Is is written that: "De7.doc is the eighth file". It is false it is the 7th. However the text in page 431 is correct. It is written that "Dxy.ext the "y" denotes the sequential number starting from one". I have resintalled an XP machine to check and I confirm that the sequence starts at 1. So "Dd5" means the fifth file deleted.
upvoted 5 times
044f354
4 months ago
The CHFI book is not wrong. There are different answers depending upon windows version, which is why the OS version is part of the question. In other words: Windows 9x family (95/98/Me): "Dd5.exe" = 6th file deleted (zero-based indexing) Windows 2000/XP (NT-based): "Dd5.exe" = 5th file deleted (one-based indexing)
upvoted 1 times
...
...
044f354
Most Recent 4 months ago
Selected Answer: A
The INFO2 file format and its indexing scheme are not comprehensively documented by Microsoft. Most of the details on how deleted files are named and tracked in the INFO2 file stem from reverse-engineering efforts and third-party forensic references rather than direct Microsoft publications. THE CHFI book is not wrong. There are different answers depending upon windows version, which is why the OS version is part of the question. In Windows 9x (Windows 95/98/Me) systems, the INFO2 file used zero-based indexing, meaning that a number like "5" actually represented the sixth file deleted (index starting at 0). When Microsoft introduced the Windows NT-based family (such as Windows 2000 and Windows XP), the indexing changed to one-based, making "5" represent the fifth file deleted. In other words: Windows 9x family (95/98/Me): "Dd5.exe" = 6th file deleted (zero-based indexing) Windows 2000/XP (NT-based): "Dd5.exe" = 5th file deleted (one-based indexing)
upvoted 1 times
...
Dumas
9 months, 3 weeks ago
Prior to Vista Drive starts with 0. The Sixth file D is the correct ans.
upvoted 1 times
...
marymayhem
1 year, 9 months ago
Selected Answer: D
Page 429 "De7.doc = (File is deleted from E: drive, it is the “eighth” file received by recycle bin, and is a “doc” file)"
upvoted 1 times
...
hisham
1 year, 11 months ago
Selected Answer: D
Agreed for @Adi_N, but the sequential number should be increased by "1" as per CHFI V10 book Also As per CHFI V10 book example : De7.doc : d drive, eighth file deleted, doc extension Another reference : https://jeffpar.github.io/kbarchive/kb/136/Q136517/
upvoted 1 times
hisham
1 year, 11 months ago
sorry for mistyping error, e drive not d
upvoted 1 times
...
...
Adi_N
2 years, 7 months ago
Prior to Windows Vista, a file in the Recycle Bin was stored in its physical location and renamed using the syntax: D<original drive letter of file><#>.<original extension> “D” denotes that a file has been deleted. In earlier versions of Windows, the deleted files were renamed by the OS using the following format: D<original drive letter of file><#>.<original extension> For example, in the case of a Dxy.ext file in the Recycled folder, “x” denotes the name of drive such as “C,” “D,” and others; “y” denotes the sequential number starting from one; and “ext” is the extension of the original file. So the answer should be A
upvoted 4 times
...
sampb
2 years, 10 months ago
Should be A
upvoted 2 times
...
EREBBUS
3 years, 3 months ago
answer must be A for INFO 2 (dxy.ext where D means delete, x the drive letter and y y the file delete and the extension)
upvoted 4 times
...
vroche
3 years, 3 months ago
Assuming WindowsXP the right answer is A - Reference https://abelcheung.github.io/rifiuti2/assets/Forensics_Recycle_Bin.pdf
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago