CompTIA SecurityX Certification Exam CAS-004 Question # 156 Topic 16 Discussion

CompTIA SecurityX Certification Exam CAS-004 Question # 156 Topic 16 Discussion

CAS-004 Exam Topic 16 Question 156 Discussion:
Question #: 156
Topic #: 16

A security engineer has been informed by the firewall team that a specific Windows workstation is part of a command-and-control network. The only information the security engineer is receiving is that

the traffic is occurring on a non-standard port (TCP 40322). Which of the following commands should the security engineer use FIRST to find the malicious process?


A.

tcpdump


B.

netstar


C.

tasklist


D.

traceroute


E.

ipconfig


Get Premium CAS-004 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.