🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)140 / 145
Question 140 of 145
While reviewing Windows Security logs on a workstation flagged by the SOC, an analyst finds Event ID 4698 recorded shortly after a suspicious PowerShell session. The event shows a new task named 'SystemUpdateCheck' configured to run an executable from a user's AppData folder every 30 minutes. What activity does this log entry most directly indicate?
Reviewed for accuracy · Report an issueNext question