QuestionQ217

Tools/Systems/Programs

Ethan, a forensic investigator, has been assigned to examine a computer system suspected of involvement in malicious online activities. As part of the investigation, he must determine which applications have run on the system. By reviewing this data, he can identify whether malicious software was installed. To collect this information, Ethan needs to inspect the appropriate system directory where traces of executed applications are stored. Which directory should Ethan examine to locate traces of applications that have been run on the system?

  • A Process Dumper
  • B Prefetch
  • C Rplog
  • D Changelog
Explanation

Windows Prefetch files record execution-related information for many applications that have run on a system. These artifacts can help forensic investigators identify programs, including potentially malicious software, that were executed.

Community Discussion

No comments yet. Be the first to start the discussion!