CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 50: 312-39V2: Certified SOC Analyst (CSA) v2

A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?

Nội dung câu hỏi

A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Review Event ID 5145 to see if unauthorized network shares were accessed
  2. B. Search for Event ID 4688 to find similar PowerShell executions within the last 24 hours — đáp án hiện tại
  3. C. Investigate Event ID 7045 to determine if a malicious service was created
  4. D. Look for Event ID 4625 to check for failed authentication attempts before execution

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề