GCFA Introduction to Memory Forensics • Set 4
GCFA Introduction to Memory Forensics Practice Test 4 — 15 questions with explanations. Free, no signup.
You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.