Verified Q&A Bank
Free Practice Question #16374
In a remote workforce involving the SIEM rule set and medical records, EDR alerts on a tool reading LSASS memory shortly after admin login. Which activity should be suspected?
+1-0
MCQA
Credential dumpingB
Data classificationC
Clean desk auditD
RAID rebuildCompTIA-SecurityPlusSY0-701practice-test-05domain-2-threats-vulnerabilities-mitigations2.4-malicious-activitycredential-dumpingdifficulty-3
Want to try a full mock exam?
Unlock the full timed mock test series for CompTIA-SecurityPlus to see detailed analytics and compete on the leaderboard.
Start Full Test Series