GCFA • Practice Test 13
Free GCFA practice test — 15 questions with explanations. Set 13. No signup required.
During an enterprise incident response, you are examining a compromised Windows system and suspect the attacker used a rootkit to hide a malicious service. You have obtained a memory image and a disk image. Which of the following techniques is most effective for detecting a hidden service that is not visible through standard API calls?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.