100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
CHFI Chapter 5-6 Questions with 100% Verified Solutions $13.24   Add to cart

Exam (elaborations)

CHFI Chapter 5-6 Questions with 100% Verified Solutions

 0 view  0 purchase
  • Course
  • Classroom
  • Institution
  • Classroom

CHFI Chapter 5-6 Questions with 100% Verified Solutions

Preview 2 out of 15  pages

  • October 22, 2024
  • 15
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • Classroom
  • Classroom
avatar-seller
Examsplug
CHFI Chapter 5-6 Questions with 100%
Verified Solutions


NETSTAT - ✔✔an to look for suspicious connections AND -ano for also Process ID




Tasklist tool - ✔✔displays the list of applications and services along with the Process IDs
(PID) for all tasks that running on either a local or a remotely connected computer



Pslist.exe - ✔✔displays basic information about the already running processes on a
system, including the amount of time each process has been running. -x details about
threads and memory, -t task tree, -d detail, -m memory, -e exact match for process name



ListDLLs - ✔✔reports DLLs loaded into processes. Process name, Pid, Dll name, -r relocated, -
u unsigned, -v version



Handle - ✔✔displays information about open handles for any process. -a all types, -c close, -
l sizes, -y no prompt, -s print count, -u username, -p processes, name Process Memory

, ProcDump - ✔✔monitor applications for CPU spikes and generating crash dumps during a
spike so that an administrator or developer can determine the cause of the spike



Process Dumper (PD) - ✔✔forensically dumps the memory of a running process




Process Explorer - ✔✔shows the information about the handles and DLLs of the
processes which have been opened or loaded



PMDump - ✔✔a tool that lets you dump the memory contents of a process to a file
without stopping the process. This tool is highly useful in forensic investigations



Ipconfig - ✔✔Displays IP/MAC information about the interfaces on the system




Print Spool Files - ✔✔These can be found at c:\windows\system32\spool\Printers




Other volatile Information to collect - ✔✔Clipboard Contents, Service/Driver
Information, Command History, Mapped Drive and Shares



The system stores the information about shared files and folders in the following registry root
key: -
✔✔HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Shares




Important Registry Entries: - ✔✔ClearPageFileAtShutdown

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller Examsplug. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $13.24. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

80467 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$13.24
  • (0)
  Add to cart