Exam 312-49v11 Topic 1 Question 307 Discussion
Actual exam question for EC-COUNCIL's 312-49v11 exam
Question #: 307
Topic #: 1
Question #: 307
Topic #: 1
A digital forensics investigator is analyzing the memory dump from a suspicious computer using the Bulk Extractor tool. He found a domain associated with Gmail (mail.google.com) and an associated Gmail ID. From the json.txt file, he discovered an email composed from the browser with an attachment. He also found an opened email with a different attachment in the memory dump. After identifying these items, what should be the investigator's next immediate step?
Suggested Answer: B Vote an answer
by Tobey at Nov 23, 2025, 05:35 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).