Câu 171: CS0-003: CompTIA CySA+ (CS0-003)
An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on its infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files f…
Nội dung câu hỏi
An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on its infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause? (Choose two.)
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Creation time of dropper
- B. Registry artifacts — đáp án hiện tại
- C. EDR data
- D. Prefetch files
- E. File system metadata — đáp án hiện tại
- F. Sysmon event log
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.