Answered step by step
Verified Expert Solution
Link Copied!

Question

00
1 Approved Answer

You will use the volatility output text files located in the CYBV 4 0 0 network folder in your Virtual Learning Environment VM to answer

You will use the volatility output text files located in the CYBV 400 network folder in your Virtual Learning Environment VM to answer this question.
Review the psxview text file.
Find the wsmprovhost.ex process
Notice there are two.
One shows an entry of True in every column. Meaning it has not attempted to hide.
Find the instance of this process where the pslist column shows an entry of False.
The PID 464 where the psscan column is true, but all other columns are false SHOULD indicate the process is no longer in memory and would therefore NOT be suspicious. You should see an exit time, but here you do not. That is suspicious.
From the list below, select the memory address of the PID 464 where the psscan column is true, but all other columns are false?
Question 11 options:
0x0000000039a65700
0x00000000835a8900
0x0000000102a4a900
0x00000001097f2400

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access with AI-Powered Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Students also viewed these Databases questions