VMware 5V0-93.22 Exam - Topic 4 Question 5 Discussion
A security administrator is tasked to investigate an alert about a suspicious running process trying to modify a system registry.Which components can be checked to further inspect the cause of the alert?
B) Event details, command lines, and TTPs involved
A) Command lines. Device ID, and priority score
C) TTPs involved, network connections, and child path
D) Priority score, file reputation, and timestamp
Sheridan
6 months agoParis
7 months agoSalley
7 months agoDenise
7 months agoFiliberto
7 months agoDorothy
7 months agoColette
8 months agoJade
8 months agoJusta
8 months agoDexter
8 months agoLillian
8 months agoGoldie
8 months agoBrett
8 months agoMica
8 months agoTambra
8 months agoPercy
8 months agoTorie
8 months ago