ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 168 - CS0-003 discussion

Report
Export

A SIEM alert is triggered based on execution of a suspicious one-liner on two workstations in the organization's environment. An analyst views the details of these events below:

Which of the following statements best describes the intent of the attacker, based on this one-liner?

A.
Attacker is escalating privileges via JavaScript.
Answers
A.
Attacker is escalating privileges via JavaScript.
B.
Attacker is utilizing custom malware to download an additional script.
Answers
B.
Attacker is utilizing custom malware to download an additional script.
C.
Attacker is executing PowerShell script 'AccessToken.psr.
Answers
C.
Attacker is executing PowerShell script 'AccessToken.psr.
D.
Attacker is attempting to install persistence mechanisms on the target machine.
Answers
D.
Attacker is attempting to install persistence mechanisms on the target machine.
Suggested answer: B

Explanation:

The one-liner script is utilizing JavaScript to execute a PowerShell command that downloads and runs a script from an external source, indicating the use of custom malware to download an additional script.Reference:CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 4: Security Operations and Monitoring, page 156.

asked 02/10/2024
Ana Rosa Abascal Ortega
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first