exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 29 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 29
Topic #: 1
[All 312-49v10 Questions]

Which is a standard procedure to perform during all computer forensics investigations?

  • A. with the hard drive removed from the suspect PC, check the date and time in the system's CMOS
  • B. with the hard drive in the suspect PC, check the date and time in the File Allocation Table
  • C. with the hard drive removed from the suspect PC, check the date and time in the system's RAM
  • D. with the hard drive in the suspect PC, check the date and time in the system's CMOS
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
044f354
2 months ago
Selected Answer: D
(D) With the hard drive in the suspect PC, check the date and time in the system's CMOS This preserves the system state and allows access to accurate date/time information.
upvoted 1 times
...
Elb
10 months, 3 weeks ago
Refer to Question #47 Topic 1 If you plan to startup a suspect's computer, you must modify the ___________ to ensure that you do not contaminate or alter data on the suspect's hard drive by booting to the hard drive.
upvoted 1 times
...
topbarry
1 year, 5 months ago
Selected Answer: D
The correct answer is D
upvoted 2 times
...
t3stk1ng
3 years ago
The evidence (the hard disk) will be tampered if you cannot boot into the CMOS. Remove a hard disk first to prevent that happen.
upvoted 4 times
...
AspiringScriptKiddie
3 years, 2 months ago
Can someone explain why this wouldn't be D? As system time/date is considered volatile data, why would one remove a hard disk first before obtaining it?
upvoted 1 times
jjweust
3 years ago
Technically, CMOS is powered by a small battery. "Nonvolatile BIOS memory refers to a small memory on PC motherboards that is used to store BIOS settings. It is traditionally called CMOS RAM because it uses a volatile, low-power complementary metal-oxide-semiconductor (CMOS) SRAM (such as the Motorola MC146818 or similar) powered by a small "CMOS" battery when system and standby power is off."
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago