Practice Test Geeks home

CREST Incident Response & Forensic Analysis 2

During a live incident, a responder notices that a Windows host has an unusual process injecting into lsass.exe.
Which tool is best suited to capture a memory dump of that specific process without rebooting?

Select your answer