GCFA Analyzing Volatile and Windows Event Artifacts • Set 2
GCFA Analyzing Volatile and Windows Event Artifacts Practice Test 2 — 15 questions with explanations. Free, no signup.
An analyst is investigating a suspected malware infection on a Windows 10 endpoint. The analyst has obtained a memory image and wants to identify processes that may be masquerading as legitimate system processes. Which two of the following techniques should the analyst use to detect process masquerading in the memory image? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.