Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCED Topic 7 Question 39 Discussion

Actual exam question for GIAC's GCED exam
Question #: 39
Topic #: 7
[All GCED Questions]

Why would an incident handler acquire memory on a system being investigated?

Show Suggested Answer Hide Answer
Suggested Answer: C

In a case study of a redirect tunnel set up on a router, some anomalies were noticed while watching network traffic with the TCPdump packet sniffer.

Packets going to port 25 (Simple Mail Transfer Protocol [SMTP] used by mail servers and other Mail Transfer Agents [MTAs] to send and receive e-mail) were apparently taking a different network path. The TLs were consistently three less than other destination ports, indicating another three network hops were taken.

Other IP header values listed, such as fragment offset. The acknowledgement number is a TCP, not IP, header field.


Contribute your Thoughts:

Jerrod
5 days ago
I'm not sure about that. Wouldn't option B be a better choice? Checking the registry for autorun entries could also be useful in an incident investigation.
upvoted 0 times
...
Lindsey
6 days ago
Option A seems like the most relevant choice here. Acquiring memory can help identify any malicious DLLs that may have been injected into running processes.
upvoted 0 times
...
Blythe
13 days ago
I believe acquiring memory can also help verify user privileges on the system.
upvoted 0 times
...
Youlanda
17 days ago
I agree with Gwenn, it's important to identify any injected applications.
upvoted 0 times
...
Gwenn
23 days ago
I think an incident handler would acquire memory to check for malicious DLLs.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77