CISA · Question #369
Which of the following computer forensics activities allows the examination of information that is only available on active operating system processes?
The correct answer is C. Primary memory imaging and analysis. Primary memory imaging and analysis allow the examination of information that is only available on active operating system processes. This type of analysis captures the contents of RAM, which can include valuable information such as running processes, encryption keys, and other…
Question
Which of the following computer forensics activities allows the examination of information that is only available on active operating system processes?
Options
- ADisk imaging and analysis
- BAntimalware log analysis
- CPrimary memory imaging and analysis
- DFirmware dumping and analysis
How the community answered
(24 responses)- A4% (1)
- B8% (2)
- C88% (21)
Explanation
Primary memory imaging and analysis allow the examination of information that is only available on active operating system processes. This type of analysis captures the contents of RAM, which can include valuable information such as running processes, encryption keys, and other transient data that is not stored on disk.
Topics
Community Discussion
No community discussion yet for this question.