CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is investigating a suspected malware infection on a Windows workstation. The analyst needs to quickly determine if any unusual processes are running and if they are communicating over the network. Which of the following commands would be MOST effective for this initial assessment?

  1. Atasklist /svc
  2. Bsfc /scannow
  3. Cipconfig /all
  4. Dnetstat -ano
Show answer & explanation

Correct answer: D. netstat -ano

The `netstat -ano` command displays active TCP connections, listening ports, and the associated process IDs (PIDs). This allows an analyst to quickly identify which processes are communicating over the network, fulfilling both requirements of the question.

Why the other options are wrong

  • A. `tasklist /svc` shows running tasks and their associated services but does not provide network connection information.
  • B. `sfc /scannow` is used to verify and repair protected system files, which is a recovery/integrity check step, not an initial assessment for running processes and network communication.
  • C. `ipconfig /all` displays network configuration information (IP address, MAC address, DNS servers, etc.) but does not show active connections or processes.

Netstat command

A command-line network utility that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics.

  • Useful for diagnosing network issues.
  • Can show listening ports and established connections.
  • The `-a` switch shows all connections, `-n` shows numerical addresses, `-o` shows the process ID.

Memory trick: To see network conversations and who's talking, you need a 'net-stat'istic.

More Incident Response and Management questions