ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 318 - SY0-601 discussion

Report
Export

A security analyst is reviewing computer logs because a host was compromised by malware After the computer was infected it displayed an error screen and shut down. Which of the following should the analyst review first to determine more information?

A.
Dump file
Answers
A.
Dump file
B.
System log
Answers
B.
System log
C.
Web application log
Answers
C.
Web application log
D.
Security too
Answers
D.
Security too
Suggested answer: A

Explanation:

A dump file is the first thing that a security analyst should review to determine more information about a compromised device that displayed an error screen and shut down. A dump file is a file that contains a snapshot of the memory contents of a device at the time of a system crash or error. A dump file can help a security analyst analyze the cause and source of the crash or error, as well as identify any malicious code or activity that may have triggered it.

Reference: https://www.comptia.org/certifications/security#examdetails https://www.comptia.org/content/guides/comptia-security-sy0-601-exam-objectives https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/introduction-to-crash- dump-files

asked 02/10/2024
eddie alvarez
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first