nerdexam
EC-Council

312-49V11 · Question #176

Kaysen, a forensic investigator, was examining a compromised Windows machine. During the investigation, Kaysen needs to collect crucial information about the applications and services running on the…

The correct answer is C. tasklist. This question aligns with CHFI v11 objectives under Operating System Forensics and Live Data Acquisition. When investigating a compromised Windows system, collecting volatile data such as running processes and active services is critical, as this information exists only in…

Windows Forensics

Question

Kaysen, a forensic investigator, was examining a compromised Windows machine. During the investigation, Kaysen needs to collect crucial information about the applications and services running on the machine to understand the impact of the breach. The investigator must gather real-time volatile evidence, such as active processes and running services, while ensuring that the data collection does not interfere with or alter the system's state. Which of the following tools will help Kaysen in the above scenario?

Options

  • AExifTool
  • BWireshark
  • Ctasklist
  • DHexinator

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    83% (24)
  • D
    7% (2)

Explanation

This question aligns with CHFI v11 objectives under Operating System Forensics and Live Data Acquisition. When investigating a compromised Windows system, collecting volatile data such as running processes and active services is critical, as this information exists only in memory and can be lost if the system is shut down. CHFI v11 emphasizes the use of native, low-impact system utilities during live forensic response to minimize changes to the system state. The tasklist command is a built-in Windows utility that displays a list of currently running processes along with associated process IDs (PIDs), memory usage, and service relationships. It is specifically designed for real-time process enumeration and is commonly used in forensic investigations to identify suspicious or malicious processes with minimal system interaction. Because tasklist is native to Windows, it does not introduce external binaries that could alter evidence integrity. ExifTool is used for metadata analysis, Wireshark captures network traffic rather than process data, and Hexinator is a hex editor used for file-level analysis, not live process enumeration. Therefore, in accordance with CHFI v11 best practices for volatile evidence collection on Windows systems, tasklist is the correct and most forensically sound tool for this scenario.

Topics

#volatile evidence#Windows forensics#active processes#tasklist command

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice