GIAC
GCED · Question #64
Why would an incident handler acquire memory on a system being investigated?
The correct answer is C. To list which services are installed on they system. You've hit your limit · resets 1pm (America/New_York)
Data Protection and Incident Response
Question
Why would an incident handler acquire memory on a system being investigated?
Options
- ATo determine whether a malicious DLL has been injected into an application
- BTo identify whether a program is set to auto-run through a registry hook
- CTo list which services are installed on they system
- DTo verify which user accounts have root or admin privileges on the system
How the community answered
(36 responses)- A8% (3)
- B3% (1)
- C86% (31)
- D3% (1)
Explanation
You've hit your limit · resets 1pm (America/New_York)
Topics
#memory acquisition#digital forensics#incident handling#volatile data
Community Discussion
No community discussion yet for this question.