Valid CAS-005 Dumps shared by EduDump.com for Helping Passing CAS-005 Exam! EduDump.com now offer the newest CAS-005 exam dumps, the EduDump.com CAS-005 exam questions have been updated and answers have been corrected get the newest EduDump.com CAS-005 dumps with Test Engine here:
During a security assessment using an EDR solution, a security engineer generates the following report about the assets in the system: After five days, the EDR console reports a blocked infection on the host 0WIN23 by a remote access Trojan. Which of the following most likely enabled the attempted infection?
Correct Answer: D
The key clue is the "Enabled (bypass)" status on 0WIN29. That means the EDR agent was running but being bypassed, effectively allowing malicious code to execute unchecked. An attacker could exploit that bypass to install the RAT on 0WIN29, and then attempt lateral movement to 0WIN23. 0WIN23's EDR then detected and blocked the inbound infection, but the initial foothold was enabled by the vulnerability in the 0WIN29 deployment.