List of questions
Related questions
Question 232 - CS0-003 discussion
A threat hunter seeks to identify new persistence mechanisms installed in an organization's environment. In collecting scheduled tasks from all enterprise workstations, the following host details are aggregated:
Which of the following actions should the hunter perform first based on the details above?
A.
Acquire a copy of taskhw.exe from the impacted host
B.
Scan the enterprise to identify other systems with taskhw.exe present
C.
Perform a public search for malware reports on taskhw.exe.
D.
Change the account that runs the -caskhw. exe scheduled task
Your answer:
0 comments
Sorted by
Leave a comment first