GCIH Exam QuestionsBrowse all questions from this exam

GCIH Exam - Question 104


Which volatility plugin shows the command line path for a recently launched application?

Show Answer
Correct Answer: CD

The correct plugin in Volatility to show information about the command line path for a recently launched application is 'pslist'. This plugin lists the active processes on the system, and provides details such as the process ID, parent process ID, and in some configurations, the command line used to start the process. The other options ('hivelist', 'dlllist', and 'netscan') do not provide information about the command line paths for applications.

Discussion

4 comments
Sign in to comment
XBal
Mar 15, 2023

Correct answer is CmdLine but that is not listed in the options

chuzpahOption: C
Jun 7, 2023

PSlist Book 2 Page 72

chuzpahOption: C
Jun 7, 2023

The Pslist plugin lists processes, Netscan shows networking (active network connections and sockets)

847ch0n3
Mar 3, 2024

None, it's CmdLine