312-49V9 · Question #218
John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf?John is working as a computer forensics investigator for a…
The correct answer is D. Hidden running processes. See the full explanation below for the reasoning.
Question
John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf?John is working as a computer forensics investigator for a consulting firm in Canada. He is called to seize a computer at a local web caf purportedly used as a botnet server. John thoroughly scans the computer and finds nothing that would lead him to think the computer was a botnet server. John decides to scan the virtual memory of the computer to possibly find something he had missed. What information will the virtual memory scan produce?
Options
- AIt contains the times and dates of when the system was last patched
- BIt is not necessary to scan the virtual memory of a computer
- CIt contains the times and dates of all the system files
- DHidden running processes
How the community answered
(56 responses)- A5% (3)
- B2% (1)
- C9% (5)
- D84% (47)
Community Discussion
No community discussion yet for this question.