The suspicious activity described in the alert is:
C. A new program has been set to execute on system start.
This is indicated by the entry:
```
Host: Webserver01
Path: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Key Added: RunME (%appdata%\abc.exe)
```
which shows that a new registry key (`RunME`) was added under `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`, pointing to an executable file (`%appdata%\abc.exe`), indicating that a program has been configured to run automatically when the system starts.
Not only is the answer clearly understandable when looking at BanesTech comment but also understand what FIM does and now you can play process of elimination. Not be because that would be alerted by network monitoring not file integrity. Not D because definitely not file integrity. We wouldn't have an alert in FIM about IP. Between A and C, A is less likely because FIM monitors for programs and files already installed to ensure they haven't been tampered with. In addition, this alert doesn't tell us that something was downloaded by the threat actor. Hope that helps.
Of the options described above, the most correct option is C.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CS0-003 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
BanesTech
Highly Voted 1 year agoYogiT
3 months, 1 week agoFreshly
Most Recent 5 months, 3 weeks agothisguyfucks
1 year, 1 month agovoiddraco
8 months, 1 week agodeeden
1 year, 5 months ago[Removed]
1 year, 5 months agokmordalv
1 year, 7 months ago