
CertNexusCyberSec First Responder (CFR)
Domain 2Objective 3
Objective 2.3 Perform Digital Forensics. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 3)
Part of the 2.0 Analyze Attacks on Computing Environments domain, which accounts for 20% of the CYBERSEC-FIRST-RESPONDER exam.
41questions here
9free pages
11concepts
20%of the exam
Questions 11–15
- 11
A security analyst responds to a suspected ransomware infection on a Windows server. The server is still running, and the analyst needs to capture evidence that will be admissible in court. The analyst has a forensic USB drive with pre-approved tools. Which action best preserves the integrity of the volatile evidence?
Select an answer first - 12
Which of the following artifacts can be extracted from a memory dump to understand what a user was doing on a compromised system?
Select an answer first - 13
A forensic analyst is preparing to capture memory from a Linux system that is suspected of running a rootkit. The analyst wants to acquire the physical memory contents directly. Which file should the analyst target to capture the raw contents of physical memory?
Select an answer first - 14
A malware analyst is analyzing a malicious script written in PowerShell. The analyst wants to understand the obfuscation techniques used. Which approach is most appropriate for analyzing this interpreted script?
Select an answer first - 15
How does debugging help in malware analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.