GCFA Identification of Malicious and Normal Activity • Set 4
GCFA Identification of Malicious and Normal Activity Practice Test 4 — 15 questions with explanations. Free, no signup.
An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.