nerdexam
Cisco

300-215 · Question #35

Which type of record enables forensics analysts to identify fileless malware on Windows machines?

The correct answer is C. PowerShell event logs. Fileless malware typically executes via in-memory PowerShell scripts. Enabling and reviewing PowerShell event logs reveals those script executions and associated command-line activity, allowing analysts to spot malicious behavior without dropped files.

Submitted by takeshi77· Mar 6, 2026Forensics Techniques

Question

Which type of record enables forensics analysts to identify fileless malware on Windows machines?

Options

  • AIIS logs
  • Bfile event records
  • CPowerShell event logs
  • Dnetwork records

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    90% (19)

Explanation

Fileless malware typically executes via in-memory PowerShell scripts. Enabling and reviewing PowerShell event logs reveals those script executions and associated command-line activity, allowing analysts to spot malicious behavior without dropped files.

Topics

#fileless malware#Windows forensics#PowerShell logs

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice