Exam 312-49v11 Topic 1 Question 66 Discussion
Actual exam question for EC-COUNCIL's 312-49v11 exam
Question #: 66
Topic #: 1
Question #: 66
Topic #: 1
Derrick, a forensic specialist, was investigating an active computer that was executing various processes. Derrick wanted to check whether this system was used In an Incident that occurred earlier. He started Inspecting and gathering the contents of RAM, cache, and DLLs to Identify Incident signatures. Identify the data acquisition method employed by Derrick in the above scenario.
Suggested Answer: C Vote an answer
by vilcsi.mark at Jun 26, 2025, 05:28 AM
0
0
0
10
Comments
xlim398
2025-12-09 11:19:08Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).