hiexam
crowdstrike · CCFH-202 · Q424 · multiple_choice · topic_1

Which of the following is a suspicious process behavior?

Which of the following is a suspicious process behavior?
  • A.PowerShell running an execution policy of RemoteSigned
  • B.An Internet browser (eg., Internet Explorer) performing multiple DNS requests
  • C.PowerShell launching a PowerShell script
  • D.Non-network processes (e.g., notepad.exe) making an outbound network connection
Explanation
Selected Answer: D Support answer is D

Reference: examtopics_top_comment

Practice with progress tracking

Sign in to track wrong answers, get spaced-repetition reminders, and run timed exam mode.