ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 475 - SY0-601 discussion

Report
Export

A user downloaded an extension for a browser, and the user's device later became infected. The analyst who Is Investigating the Incident saw various logs where the attacker was hiding activity by deleting dat

A.
The following was observed running:New-Partition -DiskNumber 2 -UseMaximumSize -AssignDriveLetter C| Format-Volume -Driveletter C - FileSystemLabel 'New'-FileSystem NTFS - Full -Force -Confirm:$falseWhich of the following is the malware using to execute the attack?
Answers
A.
The following was observed running:New-Partition -DiskNumber 2 -UseMaximumSize -AssignDriveLetter C| Format-Volume -Driveletter C - FileSystemLabel 'New'-FileSystem NTFS - Full -Force -Confirm:$falseWhich of the following is the malware using to execute the attack?
B.
PowerShell
Answers
B.
PowerShell
C.
Python
Answers
C.
Python
D.
Bash
Answers
D.
Bash
E.
Macros
Answers
E.
Macros
Suggested answer: A

Explanation:

PowerShell is a scripting language and command-line shell that can be used to automate tasks and manage systems. PowerShell can also be used by malware to execute malicious commands and evade detection. The code snippet in the question is a PowerShell command that creates a new partition on disk 2, formats it with NTFS file system, and assigns it a drive letter C. This could be part of an attack that wipes out the original data on the disk or creates a hidden partition for storing malware or stolen data.

Reference:

https://learn.microsoft.com/en-us/powershell/module/storage/new-partition?view=windowsserver2022-ps

asked 02/10/2024
Robert Thompson
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first