GCIH Exam QuestionsBrowse all questions from this exam

GCIH Exam - Question 202


Which of the following statements describes the Volatility pstree plugin data shown in the image?

Show Answer
Correct Answer: BC

The pstree output shows a hierarchical tree structure of processes. Each process listed is shown with its process ID (PID) and parent process ID (PPID). In the provided image, we can observe that 'powershell.exe' has a PPID of 2980, which belongs to the 'cmd.exe' process. This indicates that 'cmd.exe' launched 'powershell.exe'. Hence, the correct answer is that 'Cmd.exe was used to launch Powershell.exe'.

Discussion

2 comments
Sign in to comment
Vikt0rOption: C
Dec 5, 2023

The pstree plugin output will then display a hierarchical tree structure, showing the parent-child relationships between different processes. Correct answer should be C

847ch0n3Option: C
Mar 1, 2024

clearly it's C