Question 1mediummultiple choice
Read the full Enterprise Environment Incident Response explanation →GCFA Enterprise Environment Incident Response • Complete Question Bank
Complete GCFA Enterprise Environment Incident Response question bank — all 0 questions with answers and detailed explanations.
{"process_name": "svchost.exe", "pid": 4920, "parent_pid": 872, "user": "SYSTEM", "command_line": "C:\\Windows\\System32\\svchost.exe -k netsvcs -p", "network_connections": [{"proto": "tcp", "local_ip": "10.0.0.5", "remote_ip": "192.168.1.50", "remote_port": 443}]}log_entry: {"timestamp": "2023-10-12T14:22:01Z", "event": "ServiceInstallation", "service_name": "BackdoorSvc", "bin_path": "C:\\Windows\\Temp\\svchost.exe", "user": "Admin1"}
log_entry: {"timestamp": "2023-10-12T14:25:10Z", "event": "ProcessCreation", "process": "powershell.exe", "command": "-enc YQBkAGQALQBhAGQAZwByAG8AdQBwAG0AZQBtAGJlAHIA..."}C:\> netstat -ano | findstr "ESTABLISHED" TCP 10.10.1.5:445 192.168.50.20:49152 ESTABLISHED 4 TCP 10.10.1.5:443 203.0.113.45:443 ESTABLISHED 4820
Policy: {
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::sensitive-data/*"
}]
}