nerdexam
Isaca

CISA · Question #369

Which of the following computer forensics activities allows the examination of information that is only available on active operating system processes?

The correct answer is C. Primary memory imaging and analysis. Primary memory imaging and analysis allow the examination of information that is only available on active operating system processes. This type of analysis captures the contents of RAM, which can include valuable information such as running processes, encryption keys, and other…

Submitted by minji_kr· Apr 18, 2026Protection of Information Assets

Question

Which of the following computer forensics activities allows the examination of information that is only available on active operating system processes?

Options

  • ADisk imaging and analysis
  • BAntimalware log analysis
  • CPrimary memory imaging and analysis
  • DFirmware dumping and analysis

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    88% (21)

Explanation

Primary memory imaging and analysis allow the examination of information that is only available on active operating system processes. This type of analysis captures the contents of RAM, which can include valuable information such as running processes, encryption keys, and other transient data that is not stored on disk.

Topics

#Computer Forensics#Memory Forensics#Volatile Data#Incident Response

Community Discussion

No community discussion yet for this question.

Full CISA Practice