300-215 · Question #33
A security team is notified from a Cisco ESA solution that an employee received an advertising email with an attached .pdf extension file. The employee opened the attachment, which appeared to be an e
Sign in or unlock 300-215 to reveal the answer and full explanation for question #33. The question stem and answer options stay visible for context.
Question
A security team is notified from a Cisco ESA solution that an employee received an advertising email with an attached .pdf extension file. The employee opened the attachment, which appeared to be an empty document. The security analyst cannot identify clear signs of compromise but reviews running processes and determines that PowerShell.exe was spawned by CMD.exe with a grandparent AcroRd32.exe process. Which two actions should be taken to resolve this issue? (Choose two.)
Options
- AUpload the .pdf file to Cisco Threat Grid and analyze suspicious activity in depth.
- BNo action is required because this behavior is standard for .pdf files.
- CCheck the Windows Event Viewer for security logs about the incident.
- DQuarantine this workstation for further investigation, as this event is an indication of suspicious
- EInvestigate the reputation of the sender address and temporarily block all communications with
Unlock 300-215 to see the answer
You've previewed enough free 300-215 questions. Unlock 300-215 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.