nerdexam
CompTIA

220-1102 · Question #856

A user reports that a system is performing unusually and is sending requests to an unfamiliar IP address every five minutes. Which of the following should the technician check first to troubleshoot…

The correct answer is B. Running processes. When a system is exhibiting unusual behavior by sending requests to an unfamiliar IP address, the technician should first check running processes to identify the source of this suspicious network activity. Identifying the specific process can pinpoint malware or other…

Security

Question

A user reports that a system is performing unusually and is sending requests to an unfamiliar IP address every five minutes. Which of the following should the technician check first to troubleshoot the issue?

Options

  • AApplication logs
  • BRunning processes
  • CAntivirus scans
  • DRecent system updates

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    75% (27)
  • C
    14% (5)
  • D
    3% (1)

Why each option

When a system is exhibiting unusual behavior by sending requests to an unfamiliar IP address, the technician should first check running processes to identify the source of this suspicious network activity. Identifying the specific process can pinpoint malware or other unauthorized software.

AApplication logs

Application logs record events from specific applications, but they might not show the real-time, active process causing the outbound connection, and could be overwhelming to sift through without knowing the source.

BRunning processesCorrect

Checking running processes allows the technician to immediately identify what applications or services are actively running on the system and consuming resources, including initiating network connections. This helps pinpoint the specific executable responsible for sending requests to an unfamiliar IP address, which is a strong indicator of malware or unauthorized software.

CAntivirus scans

While running antivirus scans is a crucial step for malware, identifying the running process first can provide immediate insight into the threat, allow for manual termination, or help verify if existing antivirus is effective.

DRecent system updates

Recent system updates are unlikely to cause a system to repeatedly send requests to an unfamiliar IP address; this symptom points more directly to an actively running malicious or unauthorized application.

Concept tested: Identifying suspicious processes

Source: https://learn.microsoft.com/en-us/windows-server/administration/performance-monitor/monitor-application-activity

Topics

#Malware detection#Process management#System troubleshooting#Network communication

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice