CISSP Security Operations Practice Question
A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?
⚠ Common exam trap
It's easy for candidates to confuse network forensics tools (Wireshark) or disk imaging tools (EnCase, FTK Imager) with memory-specific analysis tools, forgetting that RAM analysis requires specialized frameworks like Volatility or Rekall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Volatility
Volatility (C) is the de facto open-source framework for memory forensics, designed to parse raw memory images and extract artifacts such as processes, network connections, and injected code via plugins. Rekall (D) is another memory forensics framework, originally forked from Volatility, that analyzes RAM dumps for malware and rootkit indicators. Both operate directly on memory captures, which is exactly what the analyst needs. Wireshark (A) is a network protocol analyzer that inspects packet captures, not RAM dumps. EnCase (B) and FTK Imager (E) are disk imaging and file-system forensic tools, not memory analysis frameworks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a widely used network protocol analyzer designed to capture and interactively browse the data flowing on a computer network. It operates by intercepting network packets, allowing analysts to examine their headers and payloads to understand communication patterns, troubleshoot network issues, or detect network-based attacks. However, it is entirely unsuitable for analyzing a memory dump, as it does not process the internal state of a system's RAM but rather external network traffic.
- ✗
EnCase
Why it's wrong here
EnCase is a comprehensive digital forensics platform primarily utilized for acquiring, preserving, and analyzing data from persistent storage devices such as hard drives, solid-state drives, and mobile devices. While it offers robust capabilities for disk imaging, file system analysis, and evidence recovery from non-volatile storage, it lacks the specialized parsers and plugins required to effectively interpret the complex, volatile data structures present within a system's RAM for memory forensics.
- ✓
Volatility
Why this is correct
Volatility is an industry-leading, open-source memory forensics framework specifically engineered to extract digital artifacts from volatile memory (RAM) samples. It allows security analysts to inspect the runtime state of a compromised system, identifying active processes, network connections, loaded kernel modules, and even extracting cached files, cryptographic keys, or injected code. Its extensive plugin architecture makes it indispensable for incident response, malware analysis, and advanced threat hunting by providing deep visibility into system memory.
- ✓
Rekall
Why this is correct
Rekall is a powerful and extensible memory forensics framework, originally developed as a fork of the Volatility project, providing advanced capabilities for analyzing memory dumps across various operating systems. It enables security analysts to meticulously inspect the runtime state of a system, identify malicious activity, and recover critical evidence from RAM by parsing complex kernel data structures. Rekall offers similar functionality to Volatility, focusing on robust artifact extraction and analysis for incident response and malware investigation.
- ✗
FTK Imager
Why it's wrong here
FTK Imager is a free, standalone software tool primarily used for creating forensic images of hard drives, logical drives, or specific files, and for previewing their contents without altering the original evidence. While it possesses the capability to capture live memory from an active system, its core functionality and analytical features are not designed for the in-depth interpretation of complex data structures within a memory dump for forensic analysis. It serves more as an acquisition and preview tool rather than a comprehensive memory analysis platform.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.