問題文
On a running Linux host, an analyst needs the command line and the open files of a suspicious process. Which approach obtains that while the host stays powered on?
選択肢
- Power the host off and inspect the memory image, which holds the command line of every process that was running at the moment the power was cut.
- Read the package database.
- Read the process entries the kernel exposes for that process identifier, and list the descriptors it currently holds.
- Take a disk image first and read the command line from it, because the arguments a process was started with are written to the file system when the process starts and the image therefore contains everything that a live examination would show without the risk of altering the running system.