GCFA Analyzing Volatile and Windows Event Artifacts • Set 3
GCFA Analyzing Volatile and Windows Event Artifacts Practice Test 3 — 15 questions with explanations. Free, no signup.
A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.