Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmasmnth

A SOC analyst detects multiple instances of powershell.

A SOC analyst detects multiple instances of powershell.exe being launched with the -ExecutionPolicy Bypass and -NoProfile arguments on a domain controller. The parent process is winrm.exe, and the activity occurs during non-business hours. What should be the analyst’s primary focus?

A.

Look for Event ID 4625 to check for failed authentication attempts before execution

B.

Investigate Event ID 7045 to determine if a malicious service was created

C.

Search for Event ID 4688 to find similar PowerShell executions within the last 24 hours

D.

Review Event ID 5145 to see if unauthorized network shares were accessed

ECCouncil 312-39 Summary

  • Vendor: ECCouncil
  • Product: 312-39
  • Update on: Mar 24, 2026
  • Questions: 200
Price: $52.5  $149.99
Buy Now 312-39 PDF + Testing Engine Pack

Payments We Accept

Your purchase with ExamsVCE is safe and fast. Your products will be available for immediate download after your payment has been received.
The ExamsVCE website is protected by 256-bit SSL from McAfee, the leader in online security.

examsvce payment method