Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst is investigating a host that is exhibiting suspicious behavior, including unexpected outbound connections and high CPU usage. The analyst gathers a memory dump from the compromised system. Which type of analysis is being performed?
- AApplication forensics
- BDisk forensics
- CMemory forensics
- DNetwork forensics
Show answer & explanationAnswer & explanation
Correct answer: C. Memory forensics
Memory forensics involves analyzing the contents of a computer's RAM (memory dump) to extract volatile data, such as running processes, network connections, and loaded modules, which can reveal evidence of malware or unauthorized activity.
Why the other options are wrong
- A. Application forensics focuses on analyzing specific application logs, data, or binaries.
- B. Disk forensics analyzes data stored on persistent storage devices like hard drives.
- D. Network forensics analyzes network traffic (packets) to understand communication.
Memory Forensics
The process of analyzing a computer's volatile memory (RAM) to identify and extract artifacts of malicious activity or system state.
- Captures running processes, open network connections, loaded modules, and user activity.
- Crucial for detecting fileless malware or sophisticated attacks that reside only in memory.
- Tools like Volatility Framework are commonly used.
Memory trick: Host forensics: Where the digital clues are found on the machine itself!