After successfully compromising a remote host, a security consultant notices an endpoint protection software is running on the host. Which of the following commands would be
best for the consultant to use to terminate the protection software and its child processes?
The taskkill command is used in Windows to terminate tasks by process ID (PID) or image name (IM). The correct command to terminate a specified process and any child processes which were started by it uses the /T flag, and the /F flag is used to force terminate the process. Therefore, taskkill /PID <PID> /T /F is the correct syntax to terminate the endpoint protection software and its child processes.
The other options listed are either incorrect syntax or do not accomplish the task of terminating the child processes:
* /IM specifies the image name but is not necessary when using /PID.
* /S specifies the remote system to connect to and /U specifies the user context under which the command should execute, neither of which are relevant to terminating processes.
* There is no /P flag in the taskkill command.
Kenneth
5 months agoArlette
5 months agoLanie
5 months agoArlette
5 months agoLorenza
5 months agoVallie
4 months agoShonda
4 months agoCelia
4 months agoCandida
4 months agoClorinda
6 months agoGladys
6 months agoAshleigh
5 months agoMargo
5 months agoLili
6 months agoRossana
5 months agoGerri
5 months agoSharika
5 months ago