Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 212-89 Topic 3 Question 63 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 63
Topic #: 3
[All 212-89 Questions]

Clark is investigating a cybercrime at TechSoft Solutions. While investigating the case,

he needs to collect volatile information such as running services, their process IDs,

startmode, state, and status.

Which of the following commands will help Clark to collect such information from

running services?

Show Suggested Answer Hide Answer
Suggested Answer: C

WMIC (Windows Management Instrumentation Command-line) is a command-line tool that provides a unified interface for Windows management tasks, including the collection of system information. It allows administrators and forensic investigators to query the live system for information about running services, their process IDs, start modes, states, and statuses, among other data. The use of WMIC is particularly valuable in incident response scenarios for gathering volatile information from a system without having to install additional software, which might alter the state of the system being investigated. By executing specific WMIC commands, Clark can extract detailed information about the services running on a system at the time of the investigation, making it an essential tool for collecting volatile data in a forensically sound manner.


Contribute your Thoughts:

Bobbye
3 months ago
C) wmic is the way to go, but I hope Clark has a cup of coffee handy. That command can be a real data firehose!
upvoted 0 times
...
Sabine
3 months ago
As a cybercrime investigator, Clark needs all the intel he can get. C) wmic is the way to go - it's like having a cheat sheet for the system.
upvoted 0 times
...
Linn
3 months ago
C) wmic is the clear winner. It's like having a crystal ball that reveals all the secrets of the running services.
upvoted 0 times
Colene
2 months ago
C) wmic
upvoted 0 times
...
Nydia
3 months ago
B) netstat --ab
upvoted 0 times
...
Cordelia
3 months ago
A) Openfiles
upvoted 0 times
...
...
Dorthy
4 months ago
B) netstat --ab might also be useful, but I think C) wmic is the most comprehensive option here.
upvoted 0 times
Ernie
3 months ago
I think A) Openfiles could also be helpful in this situation.
upvoted 0 times
...
Mitsue
3 months ago
I agree, C) wmic is the best option for collecting that information.
upvoted 0 times
...
...
Lashon
4 months ago
I think 'net file' could also be a potential command for collecting the required information.
upvoted 0 times
...
Rueben
4 months ago
Definitely C) wmic. It's the Swiss Army knife of service management commands. Clark will be able to collect all that juicy data in no time.
upvoted 0 times
...
Krissy
4 months ago
I think 'Openfiles' might also be a good option for Clark to use in this situation.
upvoted 0 times
...
Michell
4 months ago
Looks like C) wmic is the way to go. That command can give us all the details we need on running services.
upvoted 0 times
Vesta
4 months ago
Yes, wmic will provide us with all the necessary details about the running services.
upvoted 0 times
...
Willie
4 months ago
I think wmic is the most efficient command for this task.
upvoted 0 times
...
Lizbeth
4 months ago
I agree, wmic is definitely the best option for collecting information on running services.
upvoted 0 times
...
...
Kimbery
4 months ago
I disagree, I believe the command 'wmic' would be more suitable for collecting that information.
upvoted 0 times
...
Denae
4 months ago
I think the command 'netstat --ab' will help Clark collect the information he needs.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77