ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 208 - CS0-003 discussion

Report
Export

When investigating a potentially compromised host, an analyst observes that the process BGInfo.exe (PID 1024), a Sysinternals tool used to create desktop backgrounds containing host details, has bee running for over two days. Which of the following activities will provide the best insight into this potentially malicious process, based on the anomalous behavior?

A.
Changes to system environment variables
Answers
A.
Changes to system environment variables
B.
SMB network traffic related to the system process
Answers
B.
SMB network traffic related to the system process
C.
Recent browser history of the primary user
Answers
C.
Recent browser history of the primary user
D.
Activities taken by PID 1024
Answers
D.
Activities taken by PID 1024
Suggested answer: D

Explanation:

The activities taken by the process with PID 1024 will provide the best insight into this potentially malicious process, based on the anomalous behavior. BGInfo.exe is a legitimate tool that displays system information on the desktop background, but it can also be used by attackers to gather information about the compromised host or to disguise malicious processes12. By monitoring the activities of PID 1024, such as the files it accesses, the network connections it makes, or the commands it executes, the analyst can determine if the process is benign or malicious.

asked 02/10/2024
Dustin Roberts
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first