CompTIA CySA+CS0-002 – Question004

During an incident response procedure, a security analyst collects a hard drive to analyze a possible vector of compromise. There is a Linux swap partition on the hard drive that needs to be checked. Which of the following should the analyst use to extract human-readable content from the partition?

A.
strings
B. head
C. fsstat
D. dd

Correct Answer: D