CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 85 Topic 9 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 85 Topic 9 Discussion

CS0-003 Exam Topic 9 Question 85 Discussion:
Question #: 85
Topic #: 9

An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on it infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause?

(Select two).


A.

Creation time of dropper


B.

Registry artifacts


C.

EDR data


D.

Prefetch files


E.

File system metadata


F.

Sysmon event log


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.