QuestionQ8

Threat Hunting and Detection

Clark, a security professional, discovered that one system in the organization was infected with malware and had been used to create a backdoor. Clark used an automated tool to examine the system’s memory and identify malicious activities carried out on it.

In this scenario, which of the following tools did Clark use to detect malicious activities performed on the system?

  • A Medusa
  • B Redline
  • C Shodan
  • D Wireshark
Explanation

Redline is an endpoint forensic and memory-analysis tool that supports investigation of triage-acquisition data and identification of malicious activity. Its memory and host-artifact analysis capabilities fit detection of malware-related backdoor activity on a compromised system.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!