Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 708 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 708
Topic #: 1
[All 312-49v10 Questions]

A Forensic Investigator is examining a potential malware incident on a corporate network. The investigator believes the malware might hide in the system's device drivers or alter system files and folders. Which combination of tools would be the most effective for uncovering and analyzing any potential malware hidden in these locations?

  • A. DriverView and SIGVERIF for device driver analysis and unsigned driver detection
  • B. PA File Sight and WinMD5 for file and folder monitoring and MD5 hash value computation
  • C. DriverView and FastSum for device driver analysis and file integrity checking
  • D. PA File Sight and SIGVERIF for file and folder monitoring and unsigned driver detection
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Elb
6 months ago
Selected Answer: A
DriverView utility displays a list of all device drivers currently loaded on the system. For each driver in the list, additional information, such as the load address of the driver, description, version, product name, and the company that created the driver, is displayed. File Signature Verification, also called Sigverif, is an inbuilt Microsoft utility in Windows 10/8/7. It checks the integrity of critical files that have been digitally signed by Microsoft. It thus can help investigators find unsigned drivers.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...