Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-39 Exam - Topic 4 Question 123 Discussion

A leading e-commerce company relies on backend servers for processing customer transactions. You are working with their cybersecurity team as a SOC analyst. One morning, you notice a sharp increase in CPU utilization on one of your backend servers. Your team scans and monitors the server and finds that an unknown process is running, consuming excessive resources. You further perform detailed forensic analysis and identify the presence of an unrecognized scheduled task that triggers a PowerShell script connecting to an unknown IP address. What should you do to confirm whether this is an active attack?
A) Analyze the network logs to identify external connections
B) Check file integrity and detect recent unauthorized changes
C) Analyze the system logs for unauthorized changes
D) Review user access logs for unauthorized activity

Eccouncil 312-39 Exam - Topic 4 Question 123 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 123
Topic #: 4
[All 312-39 Questions]

A leading e-commerce company relies on backend servers for processing customer transactions. You are working with their cybersecurity team as a SOC analyst. One morning, you notice a sharp increase in CPU utilization on one of your backend servers. Your team scans and monitors the server and finds that an unknown process is running, consuming excessive resources. You further perform detailed forensic analysis and identify the presence of an unrecognized scheduled task that triggers a PowerShell script connecting to an unknown IP address. What should you do to confirm whether this is an active attack?

Show Suggested Answer Hide Answer
Suggested Answer: A

The strongest ''must-be-true'' confirmation for an active attack in this scenario is evidence of command-and-control (C2) or other suspicious external communication. You already have a scheduled task launching PowerShell and attempting to connect to an unknown IP address, which is a high-signal indicator of malicious automation. The fastest way to validate ongoing activity is to analyze network telemetry (firewall/proxy logs, netflow, EDR network events) to confirm whether outbound connections are occurring, how frequently, and whether data is being transferred. Network logs can reveal destination IP/port, protocols, connection success/failure, volume, and timing correlation with the scheduled task triggers. File integrity checks and system logs are useful for understanding persistence and modifications, but they may lag behind or miss short-lived network beacons. User access logs help attribute activity but do not directly confirm an active external control channel. From a SOC triage and containment perspective, confirming external connections enables immediate actions such as blocking the destination, isolating the host, and scoping for other systems contacting the same IPs/domains. Therefore, network log analysis is the most direct next step to confirm active malicious behavior.


Contribute your Thoughts:

0/2000 characters
Chandra
3 days ago
What if it’s just a misconfigured task? Sounds odd.
upvoted 0 times
...
Nilsa
8 days ago
I disagree, user access logs are less relevant here.
upvoted 0 times
...
Tequila
13 days ago
Wait, an unknown IP? That sounds sketchy!
upvoted 0 times
...
Ben
18 days ago
I think analyzing system logs is crucial too.
upvoted 0 times
...
Sylvia
23 days ago
Definitely check the network logs first!
upvoted 0 times
...
Aliza
29 days ago
Reviewing user access logs could also be useful, but I wonder if it would be more effective than looking at the network logs first.
upvoted 0 times
...
Kaycee
1 month ago
I feel like analyzing system logs for unauthorized changes might give us a clearer picture of what happened. We did a case study on that last week.
upvoted 0 times
...
Verdell
1 month ago
I'm not entirely sure, but checking file integrity sounds important too. If there are unauthorized changes, that could indicate a compromise.
upvoted 0 times
...
Chandra
1 month ago
I remember we practiced something similar in class, and I think analyzing the network logs could help us see if there are any suspicious connections.
upvoted 0 times
...

Save Cancel