SY0-501 · Question #427
A security analyst observes the following events in the logs of an employee workstation: 1/23 1:07:16 865 Access to C:\Users\user\temp\oasdfkh.hta has been restricted by your administrator by the defa
Sign in or unlock SY0-501 to reveal the answer and full explanation for question #427. The question stem and answer options stay visible for context.
Question
A security analyst observes the following events in the logs of an employee workstation:
1/23 1:07:16 865 Access to C:\Users\user\temp\oasdfkh.hta has been restricted by your administrator by the default restriction policy level. 1/23 1:07:09 1034 The scan is completed. No detections were found. The security analyst reviews the file system and observes the following:
C:>dir C:\Users\user\temp 1/23 1:07:02 oasdfkh.hta 1/23 1:07:02 update.bat 1/23 1:07:02 msg.txt Given the information provided, which of the following MOST likely occurred on the workstation?
Options
- AApplication whitelisting controls blocked an exploit payload from executing.
- BAntivirus software found and quarantined three malware files.
- CAutomatic updates were initiated but failed because they had not been approved.
- DThe SIEM log aged was not tuned properly and reported a false positive.
Unlock SY0-501 to see the answer
You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.