Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 9 Question 29 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 29
Topic #: 9
[All 350-201 Questions]

A security analyst receives an escalation regarding an unidentified connection on the Accounting A1 server within a monitored zone. The analyst pulls the logs and discovers that a Powershell process and a WMI tool process were started on the server after the connection was established and that a PE format file was created in the system directory. What is the next step the analyst should take?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Sanjuana
5 months ago
C could be useful too, but we need to act fast!
upvoted 0 times
...
Yun
5 months ago
Surprised this is even a question, A is the only logical choice here!
upvoted 0 times
...
Shayne
5 months ago
A seems like the safest bet, but what if it was just a scheduled task?
upvoted 0 times
...
Norah
5 months ago
I think B makes more sense, contacting the owner first could clarify things.
upvoted 0 times
...
Anisha
6 months ago
Definitely A, isolating the server is crucial!
upvoted 0 times
...
Elbert
6 months ago
This looks like a straightforward question about formatting a ticket number sequence. I'll need to carefully consider the requirements around the date and number of digits.
upvoted 0 times
...
Veronika
6 months ago
Hmm, I'm not entirely sure about this one. I'll need to review my notes on NAS and EMM procedures to make sure I understand the differences between them.
upvoted 0 times
...
Nilsa
6 months ago
Ah, I think I've got it. The scripts are likely in the <ORACLE_HOME>/user_projects/domains/mydomain/bin/jta-scripts directory. That makes the most sense to me.
upvoted 0 times
...

Save Cancel