nerdexam
Cisco

300-215 · Question #48

An incident responder reviews a log entry that shows a Microsoft Word process initiating an outbound network connection followed by PowerShell execution with obfuscated commands. Considering the machi

Sign in or unlock 300-215 to reveal the answer and full explanation for question #48. The question stem and answer options stay visible for context.

Submitted by valeria.br· Mar 6, 2026Incident Response Techniques

Question

An incident responder reviews a log entry that shows a Microsoft Word process initiating an outbound network connection followed by PowerShell execution with obfuscated commands. Considering the machine’s role in a sensitive data department, what is the most critical action for the responder to take next to analyze this output for potential indicators of compromise?

Options

  • ACompare the metadata of the Microsoft Word document with known templates to verify its
  • BExamine the network destination of the outbound connection to assess the credibility and
  • CConduct a behavioral analysis of the PowerShell execution pattern and deobfuscate the
  • DCorrelate the time of the outbound network connection with the user's activity log to establish a

Unlock 300-215 to see the answer

You've previewed enough free 300-215 questions. Unlock 300-215 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#incident response#PowerShell forensics#obfuscation#IOC identification#endpoint forensics
Full 300-215 Practice