300-215 · Question #48
An incident responder reviews a log entry that shows a Microsoft Word process initiating an outbound network connection followed by PowerShell execution with obfuscated commands. Considering the machi
Sign in or unlock 300-215 to reveal the answer and full explanation for question #48. The question stem and answer options stay visible for context.
Question
An incident responder reviews a log entry that shows a Microsoft Word process initiating an outbound network connection followed by PowerShell execution with obfuscated commands. Considering the machine’s role in a sensitive data department, what is the most critical action for the responder to take next to analyze this output for potential indicators of compromise?
Options
- ACompare the metadata of the Microsoft Word document with known templates to verify its
- BExamine the network destination of the outbound connection to assess the credibility and
- CConduct a behavioral analysis of the PowerShell execution pattern and deobfuscate the
- DCorrelate the time of the outbound network connection with the user's activity log to establish a
Unlock 300-215 to see the answer
You've previewed enough free 300-215 questions. Unlock 300-215 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.