100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

MCFE Exam Questions and Answers 100% Verified

Rating
-
Sold
-
Pages
5
Grade
A+
Uploaded on
03-09-2024
Written in
2024/2025

MCFE Exam Questions and Answers 100% VerifiedMCFE Exam Questions and Answers 100% VerifiedMCFE Exam Questions and Answers 100% VerifiedMCFE Exam Questions and Answers 100% VerifiedMCFE Exam Questions and Answers 100% Verified How does AXIOM Process identify Encrypted files? - ANSWER - Using Passware plugins. Does an Encrypted Files artifact display what program was used to encrypt the files? - ANSWER - No What does AXIOM Process search for when identifying Encryption / Anti -forensics Tools artifacts? - ANSWER - Known executables and data structures.

Show more Read less
Institution
MCFE
Course
MCFE









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
MCFE
Course
MCFE

Document information

Uploaded on
September 3, 2024
Number of pages
5
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

MCFE Exam Questions and
Answers 100% Verified
How does AXIOM Process identify Encrypted files? - ANSWER - Using Passware
plugins.


Does an Encrypted Files artifact display what program was used to encrypt the files?
- ANSWER - No


What does AXIOM Process search for when identifying Encryption / Anti -forensics
Tools artifacts? - ANSWER - Known executables and data structures.


What is the purpose of the REFINED RESULTS artifact categories? - ANSWER - To
help the examiner expedite their investigation by placing useful artifacts in one
category.


Explain the difference between the Google Searches and Parsed Search Queries
artifacts. - ANSWER - Google Searches is only for searched conducted on Google.
Parsed Search Queries is for all other search engines, like Bing, Yahoo, etc.


What REFINED RESULTS artifacts are used to create a Profile? - ANSWER - ONLY
Identifiers -People and Identifiers -Devices.


Name at least three sources of information for the Identifiers artifacts. - ANSWER -
Any of the columns from either Identifiers -People or Identifier -s Devices will suffice.


If a keyword Search is conducted form the FILTERS bar, what parts of an EMAIL are
searched? - ANSWER - All Parts


Where is the content of a document displayed in AXIOM Examine? - ANSWER - The
Preview Card in the Details Pane.

, What resource lists the various artifacts search for by AXIOM and the meanings of
the column values? - ANSWER - The Artifact Reference, accessed from Help >
Documentation > Artifact Reference.


Firefox and Chrome store much of their data in SQLite databases. How can the
content of SQLite databases be viewed in AXIOM Examine? - ANSWER - From the
SQLite Viewer within the File System Explorer.


Name three pieces of information displayed in AXIOM Examine for a file downloaded
using Chrome. - ANSWER - Any of the columns from the Evidence Pane or Details
Pane will suffice.


What is Session Recovery data? - ANSWER - Information such as last opened tabs,
etc. This is the information that may be stored should the browser quit
unexpectedly, or crash.


Name the database that stores/tracks most of the artifacts generated by Edge and
Internet Explorer v10 and v11. - ANSWER - WebCacheV01.dat


Where can EMAIL specific information such as Subject, To, From, and Received Time
be viewed in AXIOM Examine ? - ANSWER - The Evidence Pane or the Details Pane.


What is the potential investigative value of EMAIL Headers? - ANSWER - Headers
main contain accurate timestamps from the email servers, IP addresses, true sender
information, and more.


How can EMAILS with attachments be quickly identified ? - ANSWER - Either by
viewing the Attachments column for data, or by accessing the Email Attachments
artifact category.


When viewing a document's DETAILS, what is the difference between the Created
Date/Time and the File System Created Date/Time? - ANSWER - The Created
Date/Time comes from the document metadata, whereas the File System Created
Date/Time comes from the filesystem itself.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NursingTutor1 West Virginia University
View profile
Follow You need to be logged in order to follow users or courses
Sold
1621
Member since
2 year
Number of followers
1073
Documents
18045
Last sold
1 day ago
Nursing Tutor

Paper Due? Worry not. Hello. Welcome to NursingTutor. Here you\'ll find verified study materials for your assignments, exams and general school work. All papers here are graded A to help you get the best grade. Also, I am a friendly person so, do not hesitate to send a message in case you have a query. I wish you Luck.

3.9

442 reviews

5
210
4
76
3
87
2
21
1
48

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions