GIAC Certified Incident Handler (GCIH) — Question 11

Which of the following Volatility commands will display the date and time an image was collected?

Answer options

Correct answer: A

Explanation

The correct answer, A, uses the 'timeliner' command to retrieve the date and time an image was collected based on the specified profile and KDBG. The other options focus on different functionalities like retrieving image information, printing registry keys, or user assist data, which do not provide the collection timestamp.