QuestionQ102

Network Forensics and Traffic Analysis

Adam is a professional Computer Hacking Forensic Investigator who has been assigned a project to investigate a computer on SecureEnet Inc.’s network. The compromised system runs the Windows operating system. Adam chooses Helix Live for Windows to collect data and electronic evidence, beginning by retrieving volatile data and transferring it to the server component via TCP/IP.

Which Helix Windows Live application software will he use to retrieve volatile data and transfer it to the server component via TCP/IP?

  • A FAU
  • B FTK imager
  • C Drive Manager
  • D FSP
Explanation

The Forensic Server Project (FSP) collects volatile and selected nonvolatile data from a potentially compromised system. Its client components run on the target system and transfer the collected data to the remotely operated server component through TCP/IP, where the server stores the data and logs activity.

Community Discussion

No comments yet. Be the first to start the discussion!