GCFA Analyzing Volatile and Windows Event Artifacts • 15 Questions
15 GCFA Analyzing Volatile and Windows Event Artifacts practice questions with answers and explanations. Free, no signup.
During a live response memory analysis, you identify a process running from the 'C:\Windows\Temp' directory that has an established network connection. Which artifact should be prioritized to determine the specific parent process that spawned this suspicious executable?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.