List of questions
Related questions
Question 208 - CS0-003 discussion
When investigating a potentially compromised host, an analyst observes that the process BGInfo.exe (PID 1024), a Sysinternals tool used to create desktop backgrounds containing host details, has bee running for over two days. Which of the following activities will provide the best insight into this potentially malicious process, based on the anomalous behavior?
A.
Changes to system environment variables
B.
SMB network traffic related to the system process
C.
Recent browser history of the primary user
D.
Activities taken by PID 1024
Your answer:
0 comments
Sorted by
Leave a comment first