Câu 65: CS0-001: CompTIA CySA+ Certification Exam
When reviewing the system logs, the cybersecurity analyst noticed a suspicious log entry: wmic /node: HRDepartment1 computersystem get usernameWhich of the following combinations describes what occurred, and what action should be taken in this situation?
Nội dung câu hỏi
When reviewing the system logs, the cybersecurity analyst noticed a suspicious log entry: wmic /node: HRDepartment1 computersystem get usernameWhich of the following combinations describes what occurred, and what action should be taken in this situation?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. A rogue user has queried for users logged in remotely. Disable local access to network shares.
- B. A rogue user has queried for the administrator logged into the system. Attempt to determine who executed the command.
- C. A rogue user has queried for the administrator logged into the system. Disable local access to use cmd prompt.
- D. A rogue user has queried for users logged into in remotely. Attempt to determine who executed the command. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.