Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisEasy

A forensic investigator is examining a compromised Windows workstation. They suspect that a malicious actor used a tool to dump user credentials from memory. To confirm this, the investigator needs to analyze the contents of the system's physical memory. Which tool is commonly used in host-based forensics to acquire a complete image of volatile memory for offline analysis?

  1. AWireshark
  2. BNmap
  3. CSnort
  4. DFTK Imager
Show answer & explanation

Correct answer: D. FTK Imager

FTK Imager is a widely used forensic tool that can acquire forensic images of hard drives, logical drives, and volatile memory (RAM) from live systems, making it suitable for capturing memory for analysis of credential dumping or other in-memory artifacts.

Why the other options are wrong

  • A. Wireshark is a network protocol analyzer, used for capturing and analyzing network traffic, not memory.
  • B. Nmap is a network scanner used for network discovery and security auditing, not memory acquisition.
  • C. Snort is an intrusion detection system (IDS) that monitors network traffic for malicious activity, not a memory acquisition tool.

Memory Acquisition Tools

Software used to extract a copy of the contents of a computer's volatile memory (RAM) for forensic analysis.

  • Captures live system state.
  • Essential for detecting in-memory malware or credential dumps.
  • Examples include FTK Imager, DumpIt, WinPMEM.

Memory trick: To catch a digital ghost, you need specific tools: one for 'memory', one for 'network', one for 'scanning'.

More Host-Based Analysis questions