Spring Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ac4s65

A SOC analyst detects multiple instances of powershell.

A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?

A.

Look for Event ID 4625 to check for failed authentication attempts before execution

B.

Investigate Event ID 7045 to determine if a malicious service was created

C.

Search for Event ID 4688 to find similar PowerShell executions within the last 24 hours

D.

Review Event ID 5145 to see if unauthorized network shares were accessed

312-39 PDF/Engine
  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions
buy now 312-39 pdf
Get 65% Discount on All Products, Use Coupon: "ac4s65"