Cisco
300-215 · Question #35
Which type of record enables forensics analysts to identify fileless malware on Windows machines?
The correct answer is C. PowerShell event logs. Fileless malware typically executes via in-memory PowerShell scripts. Enabling and reviewing PowerShell event logs reveals those script executions and associated command-line activity, allowing analysts to spot malicious behavior without dropped files.
Submitted by takeshi77· Mar 6, 2026Forensics Techniques
Question
Which type of record enables forensics analysts to identify fileless malware on Windows machines?
Options
- AIIS logs
- Bfile event records
- CPowerShell event logs
- Dnetwork records
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C90% (19)
Explanation
Fileless malware typically executes via in-memory PowerShell scripts. Enabling and reviewing PowerShell event logs reveals those script executions and associated command-line activity, allowing analysts to spot malicious behavior without dropped files.
Topics
#fileless malware#Windows forensics#PowerShell logs
Community Discussion
No community discussion yet for this question.