exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 286 discussion

Actual exam question from CompTIA's CS0-002
Question #: 286
Topic #: 1
[All CS0-002 Questions]

A company employee downloads an application from the internet. After the installation, the employee begins experiencing noticeable performance issues, and files are appearing on the desktop:



Which of the following processes will the security analyst identify as the MOST likely indicator of system compromise given the processes running in Task Manager?

  • A. Chrome.exe
  • B. Word.exe
  • C. Explorer.exe
  • D. mstsc.exe
  • E. taskmgr.exe
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gnnggnnggnng
Highly Voted 2 years, 3 months ago
Selected Answer: D
The process the security analyst will identify as the MOST likely indicator of system compromise is "mstsc.exe" (Microsoft Remote Desktop Protocol). This process is used for remote desktop connections, and the fact that it is running with system privileges raises suspicion for potential malicious activity.
upvoted 11 times
2Fish
2 years, 1 month ago
Agreed. mstsc.exe running as system is suspicious, as we know that is a known method of running services with an account that has escalated privileges.
upvoted 2 times
2Fish
2 years, 1 month ago
I just checked my windows machine and mstsc, explorer, & taskmanager all run under the logged in user. So who knows. ugh
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago