Exam GCIH All QuestionsBrowse all questions from this exam
Question 153

Which malware investigation approach provides a detailed log of a system’s file system, network, registry and process activities?

    Correct Answer: B

    The investigation approach that provides a detailed log of a system's file system, network, registry, and process activities is Continuous monitoring. This method involves continuously recording activities and changes on the system, allowing for a comprehensive log that can be analyzed for malware behavior.

Discussion
XBalOption: B

Answer is "B". The Process Monitor is a tool that does Continuous Recording/Monitoring

[Removed]

Reference: 1-86,89

Vikt0rOption: D

Only two types: Continuous and Snapshot. Snapshot is the correct answer

T0mOption: D

Answer is D- Snapshot