During a forensic investigation, an examiner discovers that log files on a suspect's server have been selectively deleted. Which technique is most appropriate to recover metadata about deleted log entries?
-
A
Restore from the most recent full backup
-
B
Analyze journal or transaction logs from the file system
-
C
Reinstall the operating system to regenerate logs
-
D
Query the application's live database for missing entries