Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Which of the following is not part of the SANS six - part methodology for memory analysis? a . Dump suspicious processes and drivers b
Which of the following is not part of the SANS sixpart methodology for memory analysis?
a Dump suspicious processes and drivers
b Review network artifacts
c Identify rogue processes
d Review NetFlow records
QUESTION
What are some of the data points that can be found via memory analysis?
a Running processes
b Network connection
c Command history
d All of the above
QUESTION
Which of the following is a Window GUI tool used for memory forensics and developed by Mandiant?
a Volatility
b Strings
c Redline
d EnCase
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started