Verified Q&A Bank

Free Practice Question #16274

In a hybrid cloud involving the SIEM rule set and cardholder data, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?

+1-0
MCQ
A
Credential dumping
B
Data classification
C
RAID rebuild
D
Clean desk audit
CompTIA-SecurityPlusSY0-701practice-test-04domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3

Want to try a full mock exam?

Unlock the full timed mock test series for CompTIA-SecurityPlus to see detailed analytics and compete on the leaderboard.

Start Full Test Series