CS0-003 · Question #424
CS0-003 Question #424: Real Exam Question with Answer & Explanation
Sign in or unlock CS0-003 to reveal the answer and full explanation for question #424. The question stem and answer options stay visible for context.
Question
An analyst is investigating a phishing incident and has retrieved the following as part of the investigation: cmd.exe /c c:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - WindowStyle Hidden - ExecutionPolicy Bypass -NoLogo -NoProfile - EncodedCommand <VERY LONG STRING> Which of the following should the analyst use to gather more information about the purpose of this command?
Options
- AEcho the command payload content into 'base64 -d'.
- BExecute the command from a Windows VM.
- CUse a command console with administrator privileges to execute the code.
- DRun the command as an unprivileged user from the analyst workstation.
Unlock CS0-003 to see the answer
You've previewed enough free CS0-003 questions. Unlock CS0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.