During an investigation, a security analyst identified machines that are infected with malware the antivirus was unable to detect. Which of the following is the BEST place to acquire evidence to perform data carving?
A) The system memory
B) The hard drive
C) Network packets
D) The Windows Registry
Correct Answer:
Verified
Q91: Which of the following types of policies
Q92: A security analyst has observed several incidents
Q93: A critical server was compromised by malware,
Q94: An audit has revealed an organization is
Q95: A security analyst is reviewing vulnerability scan
Q97: A security team wants to make SaaS
Q98: A team of security analysts has been
Q99: It is important to parameterize queries to
Q100: A security analyst is reviewing the logs
Q101: A company's incident response team is handling
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents