Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Computer Hacking Forensic Investigator (CHFIv11) 312-49v11 Question # 57 Topic 6 Discussion

ECCouncil Computer Hacking Forensic Investigator (CHFIv11) 312-49v11 Question # 57 Topic 6 Discussion

312-49v11 Exam Topic 6 Question 57 Discussion:
Question #: 57
Topic #: 6

During a malware investigation at a financial institution in New York, forensic investigators executed a suspicious file on a Windows forensic workstation. Using the netstat -an command, they discovered that port 1177 had been opened and was actively connected. The investigators now need to determine whether the observed port activity is associated with legitimate services or indicative of malicious behavior. How should investigators evaluate the significance of this port activity?


A.

Review the list for any suspicious port number that is opened on the workstation


B.

Refer to online port databases


C.

Execute the suspect file on the forensic workstation


D.

Display all active TCP/IP connections along with a list of active ports using netstat -an


Get Premium 312-49v11 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.