🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

While reviewing CloudTrail logs and EDR telemetry for a Windows-based EC2 instance that hosts an internal web application, you see that WinRM spawned powershell.exe, which downloaded obfuscated script blocks from the registry, injected shellcode into memory, and opened an outbound HTTPS reverse shell. No unknown executables remain on the volume after a system reboot. According to SSCP malware categories, which type of malware is most likely responsible for this activity?

  • Kernel-level rootkit implanted in the Master Boot Record

  • Fileless malware leveraging in-memory PowerShell execution

  • Ransomware encrypting files stored on the EBS volume

  • Polymorphic worm spreading through SMB file shares

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot