GSEC • Practice Test 3 — 25 Questions
Free GSEC practice test 3 — 25 questions with explanations. No signup required.
An incident responder collects volatile data from a compromised Windows 10 workstation before pulling the power. The attacker used a custom executable that is no longer present on disk, but the responder needs to confirm which process spawned it and what child processes it created. Which artifact should the responder examine to establish this parent-child process relationship?
Choose an answer to begin — your selection is scored in the full session.
25 questions · instant feedback and full explanations after every question.