ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 43 - CS0-003 discussion

Report
Export

The analyst reviews the following endpoint log entry:

Which of the following has occurred?

A.
Registry change
Answers
A.
Registry change
B.
Rename computer
Answers
B.
Rename computer
C.
New account introduced
Answers
C.
New account introduced
D.
Privilege escalation
Answers
D.
Privilege escalation
Suggested answer: C

Explanation:

The endpoint log entry shows that a new account named ''admin'' has been created on a Windows system with a local group membership of ''Administrators''. This indicates that a new account has been introduced on the system with administrative privileges. This could be a sign of malicious activity, such as privilege escalation or backdoor creation, by an attacker who has compromised the system.

asked 02/10/2024
Musoke Kamuzze
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first