Exam4Training

Is it possible to search for unsigned files in the console?

Is it possible to search for unsigned files in the console?
A . Yes, by using the search:
NOT process_publisher_state:FILE_SIGNATURE_STATE_SIGNED
B . No, it is not possible to return a query for unsigned files.
C . Yes, by using the search:
process_publisher_state:FILE_SIGNATURE_STATE_UNSIGNED

D . Yes, by looking at signed and unsigned executables in the environment and seeing if another difference can be found, thus locating unsigned files in the environment.

Answer: C

Exit mobile version