ExamQuestions.com

Register
Login
CompTIA Advanced Security Practitioner (CASP) CAS-003 Exam Questions

CompTIA

CompTIA Advanced Security Practitioner (CASP) CAS-003

153 / 270

Question 153:

A forensic analyst suspects that a buffer overflow exists in a kernel module. The analyst executes the following command: 
image
However, the analyst is unable to find any evidence of the running shell. Which of the following of the MOST likely reason the analyst cannot find a process ID for the shell? 

Answer options:

A. The NX bit is enabled
B. The system uses ASLR
C. The shell is obfuscated
D. The code uses dynamic libraries