CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 67: 350-201: Performing CyberOps Using Core Security Technologies (CBRCOR)

After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?

Nội dung câu hỏi

After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Analyze the applications and services running on the affected workstation. — đáp án hiện tại
  2. B. Compare workstation configuration and asset configuration policy to identify gaps.
  3. C. Inspect registry entries for recently executed files.
  4. D. Review audit logs for privilege escalation events.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề