Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 212-89 Topic 5 Question 73 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 73
Topic #: 5
[All 212-89 Questions]

Clark is investigating a cybercrime at TechSoft Solutions. While investigating the case,

he needs to collect volatile information such as running services, their process IDs,

startmode, state, and status.

Which of the following commands will help Clark to collect such information from

running services?

Show Suggested Answer Hide Answer
Suggested Answer: C

WMIC (Windows Management Instrumentation Command-line) is a command-line tool that provides a unified interface for Windows management tasks, including the collection of system information. It allows administrators and forensic investigators to query the live system for information about running services, their process IDs, start modes, states, and statuses, among other data. The use of WMIC is particularly valuable in incident response scenarios for gathering volatile information from a system without having to install additional software, which might alter the state of the system being investigated. By executing specific WMIC commands, Clark can extract detailed information about the services running on a system at the time of the investigation, making it an essential tool for collecting volatile data in a forensically sound manner.


Contribute your Thoughts:

Lynelle
12 days ago
I'm not sure, but I think 'Openfiles' might also be useful in this situation.
upvoted 0 times
...
Sommer
13 days ago
I agree with Clement, 'wmic' is the right command for collecting information on running services.
upvoted 0 times
...
Ronald
15 days ago
Wmic? More like 'win-magic', am I right? That's the tool Clark needs to crack this case wide open.
upvoted 0 times
Wilford
2 days ago
I think Clark should definitely use wmic to gather the necessary data for the cybercrime investigation.
upvoted 0 times
...
Shanda
3 days ago
Yes, you're right! Wmic is a powerful tool for collecting information from running services.
upvoted 0 times
...
...
Clement
17 days ago
I believe 'wmic' would be a better option as it provides detailed information about running services.
upvoted 0 times
...
Markus
19 days ago
I think the command 'netstat --ab' will help Clark collect the information he needs.
upvoted 0 times
...
Mirta
25 days ago
C'mon, wmic is the obvious choice here. It's like having a crystal ball into your running services.
upvoted 0 times
Tamesha
9 days ago
User 2: Yeah, wmic gives you a lot of detailed information about running services.
upvoted 0 times
...
Lauran
12 days ago
User 1: I think wmic is the best option for collecting that information.
upvoted 0 times
...
...
Gayla
27 days ago
Ah, good old wmic. That's the Swiss Army knife of Windows system management tools.
upvoted 0 times
Isabella
4 days ago
User 4: wmic is like the Swiss Army knife of Windows system management tools.
upvoted 0 times
...
Glendora
7 days ago
User 3: I prefer using netstat --ab for collecting information from running services.
upvoted 0 times
...
Evette
9 days ago
User 2: Yes, wmic is very useful for that.
upvoted 0 times
...
Fatima
21 days ago
User 1: Have you tried using wmic to collect information from running services?
upvoted 0 times
...
...
Mabel
1 months ago
I'd go with C. wmic. Seems like the most comprehensive option to collect the details Clark needs.
upvoted 0 times
...
Miss
1 months ago
Wmic is the way to go! It gives you all the details you need about running services.
upvoted 0 times
Ettie
2 days ago
Openfiles might also be helpful in collecting information on running services.
upvoted 0 times
...
Timothy
6 days ago
I would go with wmic as well, it provides comprehensive information on running services.
upvoted 0 times
...
Kizzy
15 days ago
I think netstat --ab could also be useful for getting details on running services.
upvoted 0 times
...
Cherry
21 days ago
I agree, wmic is definitely the best option for collecting information on running services.
upvoted 0 times
...
...

Save Cancel