GCIH · Question #502
The Kratla Company deploys laptops running Windows or Mac OS to their employees, who connect via VPN. What tool can the incident response team use to centrally gather critical logs from these hosts…
The correct answer is D. GRR Rapid Response. GRR Rapid Response is the correct tool because it is an agent-based remote live forensics platform that supports centralized log collection and volatile data analysis across both Windows and macOS hosts.
Question
The Kratla Company deploys laptops running Windows or Mac OS to their employees, who connect via VPN. What tool can the incident response team use to centrally gather critical logs from these hosts as well as perform remote analysis of volatile data?
Options
- ASysinternals Suite
- BEyeWitness
- CPowershell Empire
- DGRR Rapid Response
How the community answered
(43 responses)- A2% (1)
- B2% (1)
- C5% (2)
- D91% (39)
Why each option
GRR Rapid Response is the correct tool because it is an agent-based remote live forensics platform that supports centralized log collection and volatile data analysis across both Windows and macOS hosts.
Sysinternals Suite is a collection of Windows-only utilities that must be run locally or via PsExec; it provides no centralized multi-host collection capability and does not support macOS.
EyeWitness is a reconnaissance tool for capturing screenshots of web interfaces and harvesting HTTP headers, not a platform for incident response log collection or volatile data analysis.
PowerShell Empire is a post-exploitation command-and-control framework used offensively by attackers, not a legitimate incident response tool for authorized log and volatile data collection.
GRR Rapid Response, developed by Google, deploys lightweight agents to endpoints and provides a centralized web interface for collecting artifacts, logs, and volatile data such as running processes and memory. It supports both Windows and macOS, making it purpose-built for the cross-platform, VPN-connected enterprise scenario described, unlike tools that are single-OS or lack centralized orchestration.
Concept tested: Remote live forensics tool selection for cross-platform IR
Source: https://grr-doc.readthedocs.io/en/latest/
Topics
Community Discussion
No community discussion yet for this question.