LPMQF HUNT 201 Flashcards
PowerShell has a particular syntax, which of the following is NOT one of them?
Double spaced
Which of the following does a BlueLight Torch Baseline scan address?
All hosts
True/False: PowerShell Integrated Scripting Environment is one of the two PowerShell Environments.
TRUE
Which of the following is NOT found in the C:\Tools\ directory
BlueLigHT
Putty, md5deep, Sysinternals Suite, and nc are all open source tools used by ADCCO Operators
TRUE
Which of the following is a process of a BlueLight Torch Baseline scan?
All of the above
Within the Hunter environment, in which directory is the entire BlueLight Framework kept?
J:\BlueLight
Which of the following does a BlueLight Torch Targeted scan address?
Suspicious Host
True/False: The two PowerShell environments are the PowerShell Console and Visual Studio Express.
FALSE
What command utilizes Windows Remote Management (WinRM) to access remote host information?
Invoke-Command
Where is the ADCCO Encrypted container mounted?
J:\
Which of the following is a process of a BlueLight Torch Baseline scan?
All of the Above
What Cmdlet provides the ?man page? for a Cmdlet?
Get-Help
Which data creates logs showing all connections (netflow information) on the network?
Bro
In order to transfer encrypted files between Linux and Windows VM?s, which open source tool is used? (Choose the best answer)
WinSCP