Q7
Single choice
A threat hunter discovers a true negative event from a zero-day exploit that is using privilege escalation to
launch "Malware pdf.exe".
Which XQL query will always show the correct user context used to launch "Malware pdf.exe"?