Courseiva

200-201

Full exam simulation

2:00:00
1
hard

An analyst is reviewing Sysmon logs from a compromised host. They see Event ID 1 (Process creation) for cmd.exe with parent process winword.exe. What does this indicate?

0 of 48 answered