QuestionQ211
Logs and Network ForensicsA forensic team at a multinational corporation is investigating a suspected data breach. After carefully reviewing system logs, the team finds consistent outbound traffic from an internal system to a suspicious IP address associated with dark web activity. On examining the affected system, they determine that the user had used TOR for unauthorized activities. To obtain additional evidence of TOR use, which of the following techniques is least likely to produce substantial results?
- A Scanning Prefetch files for instances of TOR execution.
- B Analyzing Command Prompt history for traces of TOR-related commands.
- C Monitoring real-time network traffic to identify connections to TOR nodes.
- D Inspecting the Windows Registry for TOR-related entries.
Community Discussion