nerdexam
EC-Council

312-49V11 · Question #176

312-49V11 Question #176: Real Exam Question with Answer & Explanation

Sign in or unlock 312-49V11 to reveal the answer and full explanation for question #176. The question stem and answer options stay visible for context.

Question

Kaysen, a forensic investigator, was examining a compromised Windows machine. During the investigation, Kaysen needs to collect crucial information about the applications and services running on the machine to understand the impact of the breach. The investigator must gather real-time volatile evidence, such as active processes and running services, while ensuring that the data collection does not interfere with or alter the system's state. Which of the following tools will help Kaysen in the above scenario?

Options

  • AExifTool
  • BWireshark
  • Ctasklist
  • DHexinator

Unlock 312-49V11 to see the answer

You've previewed enough free 312-49V11 questions. Unlock 312-49V11 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full 312-49V11 Practice