List of questions
Related questions
Question 206 - CS0-003 discussion
An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on it infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause?
(Select two).
A.
Creation time of dropper
B.
Registry artifacts
C.
EDR data
D.
Prefetch files
E.
File system metadata
F.
Sysmon event log
Your answer:
0 comments
Sorted by
Leave a comment first