Questions
- Which of the following are sources of RAM?
a. Physical memory
b.
Pagefile.mem
c. Swap
file.page
d. ROM
- Which file is created when the computer goes to sleep?
a.
Page file.sys
b.
Swap file.sys
c.
Hiberfill.sys
d.
Hibernation.sys
- When should you capture RAM?
a. Every hour
b. Every week
c. Every digital forensic investigation
d. When you deem it important
- In general, how many items do you need in order to collect RAM?
a. 1
b. 2
c. 3
d. 4
- DumpIt is a GUI tool.
a. True
b. False
- It is acceptable to install DumpIt on the suspect computer.
a. True
b. False
- Which of the following are analysis tools?
a. DumpIt
b. FTK Imager
c. Volatility
d. MD5 hash