200-201 Host-Based Analysis • Set 10
200-201 Host-Based Analysis Practice Test 10 — 15 questions with explanations. Free, no signup.
A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.