SY0-701 Threats, Vulnerabilities, and Mitigations • Set 15
SY0-701 Threats, Vulnerabilities, and Mitigations Practice Test 15 — 15 questions with explanations. Free, no signup.
Based on the exhibit, what is the most likely explanation for the suspicious workstation activity?
EDR summary: - Parent process: taskeng.exe - Child process: powershell.exe -NoProfile -WindowStyle Hidden -EncodedCommand ... - No new executable files were created in user profile folders - Scheduled task 'UpdateSvc' launches every 5 minutes - Outbound TLS connections to 198.51.100.77 occur immediately after execution