Questions
Answer the following questions to test your knowledge of this chapter:
- In an incident investigation, it may not be necessary to obtain a full disk or memory image before an analysis can be conducted.
- True
- False
- Which of the following are not advantages of an EDR platform?
- Cost
- Scalability of investigation
- Event alerting
- Central management
- The one advantage to Velociraptor is that all of the processing is done on the Velociraptor server.
- True
- False