ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 175 - CS0-003 discussion

Report
Export

An employee downloads a freeware program to change the desktop to the classic look of legacy Windows. Shortly after the employee installs the program, a high volume of random DNS queries begin to originate from the system. An investigation on the system reveals the following:

Add-MpPreference -ExclusionPath '%Program Filest\ksysconfig'

Which of the following is possibly occurring?

A.
Persistence
Answers
A.
Persistence
B.
Privilege escalation
Answers
B.
Privilege escalation
C.
Credential harvesting
Answers
C.
Credential harvesting
D.
Defense evasion
Answers
D.
Defense evasion
Suggested answer: D

Explanation:

Defense evasion is the technique of avoiding detection or prevention by security tools or mechanisms. In this case, the freeware program is likely a malware that generates random DNS queries to communicate with a command and control server or exfiltrate data. The command Add-MpPreference -ExclusionPath '%Program Filest\ksysconfig' is used to add an exclusion path to Windows Defender, which is a built-in antivirus software, to prevent it from scanning the malware folder.

Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 5, page 204; CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 5, page 212. pr

asked 02/10/2024
Anton Khodyakov
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first