During Apple Systems Triage, what is essential for identifying user accounts?
During an incident response investigation, which macOS artifacts can provide evidence of malware execution? (Select two)
Which log file is essential for identifying malware behavior on macOS during an incident response?
What type of encryption is used by default on modern macOS drives?
What type of event artifacts are generated by Spotlight on macOS? (Select two)
Which command is used to mount a disk image on macOS for forensic analysis?
During an investigation of an iPhone, you need to gather evidence of a suspect's recent locations. The Maps application shows several recent trips, but you are unsure of their exact destinations.
Which steps will you take to analyze the Maps application data to confirm the locations? (Select three correct answers)
In incident response, what indicates a potential security breach in an Apple operating system?
What macOS feature is crucial for isolating and analyzing suspicious applications during an incident response?