nerdexam
EC-Council

312-49V9 · Question #218

John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf?John is working as a computer forensics investigator for a…

The correct answer is D. Hidden running processes. See the full explanation below for the reasoning.

Question

John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf?John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?

Options

  • AIt contains the times and dates of when the system was last patched
  • BIt is not necessary to scan the virtual memory of a computer
  • CIt contains the times and dates of all the system files
  • DHidden running processes

How the community answered

(56 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    9% (5)
  • D
    84% (47)

Community Discussion

No community discussion yet for this question.

Full 312-49V9 Practice