Câu 50: 312-39V2: Certified SOC Analyst (CSA) v2
A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?
Nội dung câu hỏi
A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Review Event ID 5145 to see if unauthorized network shares were accessed
- B. Search for Event ID 4688 to find similar PowerShell executions within the last 24 hours — đáp án hiện tại
- C. Investigate Event ID 7045 to determine if a malicious service was created
- D. Look for Event ID 4625 to check for failed authentication attempts before execution
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.