The RasAuto service is described as what in the source material?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

The RasAuto service is described as what in the source material?

Explanation:
RasAuto is the Windows Remote Access Auto Connection Manager, which automatically establishes network connections (such as dial-up or VPN connections) when resources are accessed. The material describes it as a disabled service that is abused by a China-based APT. This matches the idea that, by default, the service isn’t active, but if an attacker needs covert network access, they can leverage or re-enable it to establish a connection for persistence or C2. The other options misstate its purpose (not Windows updates or printer management) and don’t align with the description of being disabled and used by a specific APT.

RasAuto is the Windows Remote Access Auto Connection Manager, which automatically establishes network connections (such as dial-up or VPN connections) when resources are accessed. The material describes it as a disabled service that is abused by a China-based APT. This matches the idea that, by default, the service isn’t active, but if an attacker needs covert network access, they can leverage or re-enable it to establish a connection for persistence or C2. The other options misstate its purpose (not Windows updates or printer management) and don’t align with the description of being disabled and used by a specific APT.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy