200-201 • Practice Exam 58
Free 200-201 practice exam — 20 questions with explanations. Set 58. No signup required.
A security analyst is examining a Windows 10 endpoint suspected of compromise. The analyst runs `wmic process get name,processid,executablepath,parentprocessid` and observes a process named `lsass.exe` with PID 1234 and executable path `C:\Windows\Temp\lsass.exe`. The legitimate lsass.exe should reside in `C:\Windows\System32`. Which of the following is the MOST likely explanation?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.