CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 117: CAS-003: CompTIA Advanced Security Practitioner (CASP) CAS-003

An incident responder wants to capture volatile memory comprehensively from a running machine for forensic purposes. The machine is running a very recent release of the Linux OS. Which of the following technical approaches would be the MOST feasible way to accomplish this capture?

Nội dung câu hỏi

An incident responder wants to capture volatile memory comprehensively from a running machine for forensic purposes. The machine is running a very recent release of the Linux OS. Which of the following technical approaches would be the MOST feasible way to accomplish this capture?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Run the memdump utility with the -k flag.
  2. B. Use a loadable kernel module capture utility, such as LiME.
  3. C. Run dd on/dev/mem.
  4. D. Employ a stand-alone utility, such as FTK Imager. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề