* PID 2264 (bash running as root) is suspicious because: * It has elevated privileges (root user). * Bash (command-line shell) is running with high CPU usage (14.0%), which is unusual unless actively being used. * If unauthorized, an attacker could be exfiltrating data via command-line methods like scp, wget, or custom scripts. Why Not Other Options? * B (34218 - Xorg) # Xorg is a display server for GUI; no signs of exfiltration. * C (34834 - Cinnamon) # Cinnamon is a desktop environment, not a threat. * D (35963 - xrdp) # xrdp is a remote desktop service, expected behavior. Reference: CompTIA CySA+ CS0-003, Chapter 6: " Host-Based Security Monitoring, " Section: " Analyzing Suspicious Processes and Privileged Activity. "