Quiz 2 Question 10 of 20

During threat hunting, an analyst sees HTTP POST requests to a rarely accessed upload endpoint with Base64-encoded parameters. File system audit shows a new .php file created under the web root, and the web server process later spawns cmd.exe. Which indicator most strongly points to persistent attacker access?

Select an answer to reveal the explanation.

Motivation