CS0-003 · Question #2
The analyst reviews the following endpoint log entry: Which of the following has occurred?
The correct answer is C. New account introduced. The endpoint log entry shows that a new account named "admin" has been created on a Windows system with a local group membership of "Administrators". This indicates that a new account has been introduced on the system with administrative privileges. This could be a sign of…
Question
The analyst reviews the following endpoint log entry:
Which of the following has occurred?
Options
- ARegistry change
- BRename computer
- CNew account introduced
- DPrivilege escalation
How the community answered
(52 responses)- A10% (5)
- B4% (2)
- C85% (44)
- D2% (1)
Explanation
The endpoint log entry shows that a new account named "admin" has been created on a Windows system with a local group membership of "Administrators". This indicates that a new account has been introduced on the system with administrative privileges. This could be a sign of malicious activity, such as privilege escalation or backdoor creation, by an attacker who has compromised the system.
Topics
Community Discussion
No community discussion yet for this question.