Which of the following is a volatile evidence collecting tool?
A.
Netstat
B.
HashTool
C.
FTK Images
D.
ProDiscover Forensics
The Answer Is:
A
This question includes an explanation.
Explanation:
Netstat (network statistics) is a command-line tool that displays network connections (both incoming and outgoing), routing tables, and a number of network interface (and network protocol) statistics. It is considered a volatile evidence collecting tool because it gathers information that exists in the system's memory, which is lost upon shutdown or reboot. This makes it invaluable for collecting evidence of active connections and processes that are present at the time of the incident response but does not persistently store data that can be recovered later. This contrasts with tools like FTK Imager or ProDiscover Forensics, which are used for acquiring digital evidence in a non-volatile manner, such as disk imaging, and HashTool, which is used for validating the integrity of collected digital evidence through hashing.
[References:EC-Council's ECIH v3 materials include discussions on the importance of volatile and non-volatile evidence, emphasizing tools like Netstat for their role in the immediate collection, , ]
212-89 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"