Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 11 Topic 2 Discussion

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 11 Topic 2 Discussion

312-39 Exam Topic 2 Question 11 Discussion:
Question #: 11
Topic #: 2

A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?


A.

Look for Event ID 4625 to check for failed authentication attempts before execution


B.

Investigate Event ID 7045 to determine if a malicious service was created


C.

Search for Event ID 4688 to find similar PowerShell executions within the last 24 hours


D.

Review Event ID 5145 to see if unauthorized network shares were accessed


Get Premium 312-39 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.