nerdexam
GIAC

GCED · Question #64

Why would an incident handler acquire memory on a system being investigated?

The correct answer is C. To list which services are installed on they system. You've hit your limit · resets 1pm (America/New_York)

Data Protection and Incident Response

Question

Why would an incident handler acquire memory on a system being investigated?

Options

  • ATo determine whether a malicious DLL has been injected into an application
  • BTo identify whether a program is set to auto-run through a registry hook
  • CTo list which services are installed on they system
  • DTo verify which user accounts have root or admin privileges on the system

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    86% (31)
  • D
    3% (1)

Explanation

You've hit your limit · resets 1pm (America/New_York)

Topics

#memory acquisition#digital forensics#incident handling#volatile data

Community Discussion

No community discussion yet for this question.

Full GCED Practice