312-39 Forensic Investigation And Malware Analysis Practice Question
During an incident response, you identify a persistent malware process. You need to see exactly which files and registry keys the process is touching in real-time. Which Sysinternals tool provides this capability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process Monitor
Process Monitor (Procmon) provides real-time monitoring of file system, Registry, and process activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Autoruns
Why it's wrong here
Autoruns lists persistence points, not real-time file access.
- ✗
TCPView
Why it's wrong here
TCPView only shows network connection state, not file access.
- ✗
Process Explorer
Why it's wrong here
Process Explorer lists running processes but does not trace all file IO in real-time.
- ✓
Process Monitor
Why this is correct
Procmon tracks all file and registry activity for a given process.
About these practice questions
One of 201 original 312-39 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This 312-39 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 312-39 exam.