CompTIA CySA+ CS0-003 Practice Question

An analyst is reviewing a system's task scheduler and notices a newly added task that launches a script at midnight daily. Upon further investigation, it is found that the script is obfuscated and has no documentation regarding its purpose. To determine if this task is benign or should be elevated as a security incident, which of the following actions would BEST establish the legitimacy of the scheduled task?

  • Review the account that created the scheduled task for any correlations with other known user activities.

  • Monitor resource utilization during the task's operation to identify any abnormal consumption patterns.

  • Analyze the script's code and behavior in a sandbox environment.

  • Inspect the scheduling pattern to check for consistency with other administrative tasks.

CompTIA CySA+ CS0-003
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot