GCIH Exam QuestionsBrowse all questions from this exam

GCIH Exam - Question 153


Which malware investigation approach provides a detailed log of a system’s file system, network, registry and process activities?

Show Answer
Correct Answer: AB

The investigation approach that provides a detailed log of a system's file system, network, registry, and process activities is Continuous monitoring. This method involves continuously recording activities and changes on the system, allowing for a comprehensive log that can be analyzed for malware behavior.

Discussion

3 comments
Sign in to comment
XBalOption: B
Mar 16, 2023

Answer is "B". The Process Monitor is a tool that does Continuous Recording/Monitoring

[Removed]
Jul 30, 2023

Reference: 1-86,89

T0mOption: D
Feb 6, 2023

Answer is D- Snapshot

Vikt0rOption: D
Dec 7, 2023

Only two types: Continuous and Snapshot. Snapshot is the correct answer