CS0-003 Exam Question 166

A security analyst receives an alert for suspicious activity on a company laptop An excerpt of the log is shown below:

Which of the following has most likely occurred?
  • CS0-003 Exam Question 167

    An organization would like to ensure its cloud infrastructure has a hardened configuration. A requirement is to create a server image that can be deployed with a secure template. Which of the following is the best resource to ensure secure configuration?
  • CS0-003 Exam Question 168

    An IT professional is reviewing the output from the top command in Linux. In this company, only IT and security staff are allowed to have elevated privileges. Both departments have confirmed they are not working on anything that requires elevated privileges. Based on the output below:
    PID
    USER
    VIRT
    RES
    SHR
    %CPU
    %MEM
    TIME+
    COMMAND
    34834
    person
    4980644
    224288
    111076
    5.3
    14.44
    1:41.44
    cinnamon
    34218
    person
    51052
    30920
    23828
    4.7
    0.2
    0:26.54
    Xorg
    2264
    root
    449628
    143500
    26372
    14.0
    3.1
    0:12.38
    bash
    35963
    xrdp
    711940
    42356
    10560
    2.0
    0.2
    0:06.81
    xrdp
    Which of the following PIDs is most likely to contribute to data exfiltration?
  • CS0-003 Exam Question 169

    An incident responder was able to recover a binary file through the network traffic. The binary file was also found in some machines with anomalous behavior. Which of the following processes most likely can be performed to understand the purpose of the binary file?
  • CS0-003 Exam Question 170

    A systems administrator receives several reports about emails containing phishing links. The hosting domain is always different, but the URL follows a specific pattern of characters. Which of the following is the best way for the administrator to find more messages that were not reported?