
CertNexusCyberSec First Responder (CFR)
Domain 2Objective 3
Objective 2.3 Perform Digital Forensics. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 5)
Part of the 2.0 Analyze Attacks on Computing Environments domain, which accounts for 20% of the CYBERSEC-FIRST-RESPONDER exam.
41questions here
9free pages
11concepts
20%of the exam
Questions 21–25
- 21
In Linux, what does the virtual file /proc/kcore represent?
Select an answer first - 22
An incident responder is called to a server that is actively being compromised. The attacker is running a process that is encrypting files. The responder has a memory capture tool on a USB drive. What is the most important reason to capture memory immediately, before any other action?
Select an answer first - 23
An incident responder has captured a memory dump from a compromised Windows workstation. The responder needs to identify which malicious process was communicating with a known command-and-control server. Which tool and plugin combination is most appropriate for this task?
Select an answer first - 24
When analyzing a memory dump, which artifact would help you identify the network connections that were active at the time of capture?
Select an answer first - 25
An incident responder needs to capture memory from a live system. Which action best exemplifies minimal interaction to preserve evidence integrity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.