300-215 Web TestEngine demo

Exit VCEDump 300-215 Conducting Forensic Analysis and Incident Response Using Cisco Technologies for CyberOps (CBRFIR)
Question 6 of 18
0% complete
Q6 Single choice

During a routine inspection of system logs, a security analyst notices an entry where Microsoft Word initiated a PowerShell command with encoded arguments.
Given that the user's role does not involve scripting or advanced document processing, which action should the analyst take to analyze this output for potential indicators of compromise?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in