nerdexam
EC-CouncilEC-Council

312-49 · Question #218

312-49 Question #218: Real Exam Question with Answer & Explanation

Sign in or unlock 312-49 to reveal the answer and full explanation for question #218. The question stem and answer options stay visible for context.

Submitted by manish99· Apr 18, 2026Malware Forensics

Question

John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf?John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?

Options

  • AIt contains the times and dates of when the system was last patched
  • BIt is not necessary to scan the virtual memory of a computer
  • CIt contains the times and dates of all the system files
  • DHidden running processes

Unlock 312-49 to see the answer

You've previewed enough free 312-49 questions. Unlock 312-49 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Virtual Memory Analysis#Memory Forensics#Hidden Processes#Malware Detection
Full 312-49 PracticeBrowse All 312-49 Questions