Solved

An Incident Responder Wants to Capture Volatile Memory Comprehensively from a Running

Question 352

Multiple Choice

An incident responder wants to capture volatile memory comprehensively from a running machine for forensic purposes. The machine is running a very recent release of the Linux OS. Which of the following technical approaches would be the MOST feasible way to accomplish this capture?


A) Run the memdump utility with the -k flag. Run the memdump utility with the -k flag.
B) Use a loadable kernel module capture utility, such as LiME.
C) Run dd on/dev/mem. Run dd on/dev/mem.
D) Employ a stand-alone utility, such as FTK Imager.

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions