nerdexam
CompTIA

SY0-501 · Question #427

A security analyst observes the following events in the logs of an employee workstation: 1/23 1:07:16 865 Access to C:\Users\user\temp\oasdfkh.hta has been restricted by your administrator by the defa

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #427. The question stem and answer options stay visible for context.

Submitted by salim_om· Mar 4, 2026Security operations

Question

A security analyst observes the following events in the logs of an employee workstation:

1/23 1:07:16 865 Access to C:\Users\user\temp\oasdfkh.hta has been restricted by your administrator by the default restriction policy level. 1/23 1:07:09 1034 The scan is completed. No detections were found. The security analyst reviews the file system and observes the following:

C:>dir C:\Users\user\temp 1/23 1:07:02 oasdfkh.hta 1/23 1:07:02 update.bat 1/23 1:07:02 msg.txt Given the information provided, which of the following MOST likely occurred on the workstation?

Options

  • AApplication whitelisting controls blocked an exploit payload from executing.
  • BAntivirus software found and quarantined three malware files.
  • CAutomatic updates were initiated but failed because they had not been approved.
  • DThe SIEM log aged was not tuned properly and reported a false positive.

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#application whitelisting#HTA file#exploit payload#SRP
Full SY0-501 Practice