BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 212-89 Topic 3 Question 55 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 55
Topic #: 3
[All 212-89 Questions]

John is performing memory dump analysis in order to find out the traces of malware.

He has employed volatility tool in order to achieve his objective.

Which of the following volatility framework commands he will use in order to analyze running process from the memory dump?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Quentin
5 months ago
So, option B fits best for analyzing running processes.
upvoted 0 times
...
Charolette
5 months ago
Yes, and imageinfo provides memory image information.
upvoted 0 times
...
Salome
6 months ago
Yeah, hivelist is for registry, right?
upvoted 0 times
...
Peter
6 months ago
I think the answer is B. pslist is for running processes.
upvoted 0 times
...
Quentin
6 months ago
Agreed, you need to know Volatility commands well.
upvoted 0 times
...
Salome
6 months ago
This exam question looks tricky.
upvoted 0 times
...

Save Cancel