300-220 CBRTHD: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
By Cisco · Question Mode
QuestionQ18
Threat Hunting Techniques
Refer to the exhibit.
After receiving an alert that a Windows host authenticated over the network to another host using a local administrator account, the security team examines the host. The team finds a process-creation event in that host's Sysmon logs.
Which action did the host carry out?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion