nerdexam
EC-Council

212-89 · Question #164

John is performing memory dump analysis in order to find out the traces of malware. He has employed volatility tool in order to achieve his objective. Which of the following volatility framework comma

Sign in or unlock 212-89 to reveal the answer and full explanation for question #164. The question stem and answer options stay visible for context.

Computer Forensics in Incident Handling

Question

John is performing memory dump analysis in order to find out the traces of malware. He has employed volatility tool in order to achieve his objective. Which of the following volatility framework commands he will use in order to analyze running process from the memory dump?

Options

  • Apython vol.py svcscan --profile=Win2008SP1x86 -f /root/Desktop/memdump.mem | more
  • Bpython vol.py pslist --profile=Win2008SP1x86 -f /root/Desktop/memdump.mem
  • Cpython vol.py hivelist --profile=Win2008SP1x86 -f /root/Desktop/memdump.mem
  • Dpython vol.py imageinfo -f /root/Desktop/memdump.mem

Unlock 212-89 to see the answer

You've previewed enough free 212-89 questions. Unlock 212-89 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Volatility framework#memory forensics#pslist command#malware analysis
Full 212-89 Practice