Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CFR-310 All Questions

View all questions & answers for the CFR-310 exam

Exam CFR-310 topic 1 question 12 discussion

Actual exam question from CertNexus's CFR-310
Question #: 12
Topic #: 1
[All CFR-310 Questions]

During a security investigation, a suspicious Linux laptop is found in the server room. The laptop is processing information and indicating network activity. The investigator is preparing to launch an investigation to determine what is happening with this laptop. Which of the following is the MOST appropriate set of Linux commands that should be executed to conduct the investigation?

  • A. iperf, traceroute, whois, ls, chown, cat
  • B. iperf, wget, traceroute, dc3dd, ls, whois
  • C. lsof, chmod, nano, whois, chown, ls
  • D. lsof, ifconfig, who, ps, ls, tcpdump
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
044f354
1 month, 3 weeks ago
Selected Answer: D
D. lsof, ifconfig, who, ps, ls, tcpdump Explanation: lsof: Lists open files and network connections, helping to see what files or sockets the laptop is accessing. ifconfig: Displays network interface information, which helps determine if the laptop is connected to the network and how. who: Shows who is logged into the system, helping identify any suspicious users. ps: Displays currently running processes, useful for determining what is actively running on the laptop. ls: Lists files in a directory, helpful for seeing the contents of important directories (e.g., /tmp, /etc). tcpdump: Captures network traffic for real-time analysis, allowing you to see what network activity the laptop is engaged in.
upvoted 1 times
...
surfuganda
7 months, 1 week ago
Selected Answer: D
lsof: Lists open files and processes, which can help identify any suspicious or unauthorized processes running on the laptop. ifconfig: Displays network interface configuration, to gather information about the laptop's network connections and settings. who: Displays information about users logged into the system, providing insight into who may be using the laptop. ps: Lists currently running processes, to identify any suspicious or unauthorized processes. ls: Lists directory contents, to examine files and directories on the laptop. tcpdump: Captures and analyzes network traffic in real-time, providing visibility into network activity and helping to identify any suspicious or unauthorized network connections or traffic.
upvoted 1 times
...
Wutan
1 year, 2 months ago
Selected Answer: D
D. lsof, ifconfig, who, ps, ls, tcpdump. - lsof lists all open files on the system, including network sockets. This will help the investigator to determine which processes are accessing the network. - ifconfig displays the network configuration of the laptop. This will help the investigator to determine the laptop's IP address and other network settings. - who lists all users who are currently logged in to the laptop. This will help the investigator to identify who is using the laptop. - ps lists all running processes on the laptop. This will help the investigator to identify which processes are running and what they are doing. - ls lists the contents of the current directory. This will help the investigator to see what files are on the laptop. - tcpdump captures network traffic. This will help the investigator to see what data is being sent and received by the laptop.
upvoted 1 times
...
HeyacedoGomez
1 year, 4 months ago
Selected Answer: D
D is correct...
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...