Questions and CORRECT Answers
Powershell Commands - CORRECT ANSWER - get-
set-
WMIC Commands - CORRECT ANSWER - Process list brief
Setup list brief
Service list brief
Service get process
CMD Commands - CORRECT ANSWER - Net users
Ip config
Ping
Trace route
Wacwac x.x.x.x- (access through the internet)
netstat
GUI native tools - CORRECT ANSWER - Taskmanager
Regedit
Firewall advanced
NTFS-policy
Procmon (description) - CORRECT ANSWER - shows real-time file system, Registry and
process/thread activity
Autorun (description) - CORRECT ANSWER - startup processes
, Pslist (description) - CORRECT ANSWER - list detailed information about processes
Tcpview (description) - CORRECT ANSWER - connecting to resources on the internet
Handels (description) - CORRECT ANSWER - displays information about open handles
for any process in the system.
Strings (description) - CORRECT ANSWER - Strings just scans the file you pass it for
UNICODE (or ASCII) strings of a default length of 3 or more UNICODE (or ASCII) characters
Psinfo (description) - CORRECT ANSWER - shows information for the local system.
Specify a remote computer name to obtain information from the remote system.
Loggonsessions (description) - CORRECT ANSWER - lists the currently active logon
sessions and, if you specify the -p option, the processes running in each session
Psloggedon (description) - CORRECT ANSWER - an applet that displays both the locally
logged on users and users logged on via resources for either the local computer, or a remote one.
Procexp (description) - CORRECT ANSWER - shows you information about which
handles and DLLs processes have opened or loaded.
netstat -ano - CORRECT ANSWER - cmd
displays protocol statistics and current TCP/IP connections.
Nbtstat - CORRECT ANSWER - NetBIOS
PSList - CORRECT ANSWER - Show information about processes and threads