nerdexam
EC-Council

212-89 · Question #55

James is working as an incident responder at CyberSol Inc. The management instructed James to investigate a cybersecurity incident that recently happened in the company. As a part of the investigation

Sign in or unlock 212-89 to reveal the answer and full explanation for question #55. The question stem and answer options stay visible for context.

Computer Forensics in Incident Handling

Question

James is working as an incident responder at CyberSol Inc. The management instructed James to investigate a cybersecurity incident that recently happened in the company. As a part of the investigation process, James started collecting volatile information from a system running on Windows operating system. Which of the following commands helps James in determining all the executable files for running processes?

Options

  • Acate A &. time ,/t
  • Bnetstat -ab
  • Ctop
  • Ddoskey/history

Unlock 212-89 to see the answer

You've previewed enough free 212-89 questions. Unlock 212-89 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#volatile data collection#netstat#Windows forensics#running processes
Full 212-89 Practice