220-1102 · Question #856
A user reports that a system is performing unusually and is sending requests to an unfamiliar IP address every five minutes. Which of the following should the technician check first to troubleshoot…
The correct answer is B. Running processes. When a system is exhibiting unusual behavior by sending requests to an unfamiliar IP address, the technician should first check running processes to identify the source of this suspicious network activity. Identifying the specific process can pinpoint malware or other…
Question
A user reports that a system is performing unusually and is sending requests to an unfamiliar IP address every five minutes. Which of the following should the technician check first to troubleshoot the issue?
Options
- AApplication logs
- BRunning processes
- CAntivirus scans
- DRecent system updates
How the community answered
(36 responses)- A8% (3)
- B75% (27)
- C14% (5)
- D3% (1)
Why each option
When a system is exhibiting unusual behavior by sending requests to an unfamiliar IP address, the technician should first check running processes to identify the source of this suspicious network activity. Identifying the specific process can pinpoint malware or other unauthorized software.
Application logs record events from specific applications, but they might not show the real-time, active process causing the outbound connection, and could be overwhelming to sift through without knowing the source.
Checking running processes allows the technician to immediately identify what applications or services are actively running on the system and consuming resources, including initiating network connections. This helps pinpoint the specific executable responsible for sending requests to an unfamiliar IP address, which is a strong indicator of malware or unauthorized software.
While running antivirus scans is a crucial step for malware, identifying the running process first can provide immediate insight into the threat, allow for manual termination, or help verify if existing antivirus is effective.
Recent system updates are unlikely to cause a system to repeatedly send requests to an unfamiliar IP address; this symptom points more directly to an actively running malicious or unauthorized application.
Concept tested: Identifying suspicious processes
Source: https://learn.microsoft.com/en-us/windows-server/administration/performance-monitor/monitor-application-activity
Topics
Community Discussion
No community discussion yet for this question.