nerdexam
CompTIA

CS0-003 · Question #2

The analyst reviews the following endpoint log entry: Which of the following has occurred?

The correct answer is C. New account introduced. The endpoint log entry shows that a new account named "admin" has been created on a Windows system with a local group membership of "Administrators". This indicates that a new account has been introduced on the system with administrative privileges. This could be a sign of…

Submitted by paula_co· Mar 6, 2026Security and Compliance

Question

The analyst reviews the following endpoint log entry:

Which of the following has occurred?

Options

  • ARegistry change
  • BRename computer
  • CNew account introduced
  • DPrivilege escalation

How the community answered

(52 responses)
  • A
    10% (5)
  • B
    4% (2)
  • C
    85% (44)
  • D
    2% (1)

Explanation

The endpoint log entry shows that a new account named "admin" has been created on a Windows system with a local group membership of "Administrators". This indicates that a new account has been introduced on the system with administrative privileges. This could be a sign of malicious activity, such as privilege escalation or backdoor creation, by an attacker who has compromised the system.

Topics

#Log analysis#Endpoint security#New account detection

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice