Cisco 300-215 Exam - Topic 10 Question 66 Discussion
An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?
A) Upload the file signature to threat intelligence tools to determine if the file is malicious.
B) Monitor processes as this a standard behavior of Word macro embedded documents.
C) Contain the threat for further analysis as this is an indication of suspicious activity.
D) Investigate the sender of the email and communicate with the employee to determine the motives.
Willard
9 months agoDeeanna
10 months agoPamella
10 months agoShawnta
10 months agoBettina
10 months agoHyun
10 months agoMose
11 months agoCherry
11 months agoLai
11 months agoSheridan
11 months agoDerick
11 months agoArlyne
11 months agoDenny
11 months agoEmerson
11 months agoVashti
11 months agoAnnabelle
11 months agoKristin
11 months agoBuck
1 year agoLinwood
1 year agoChu
1 year agoGeraldine
1 year agoTequila
1 year agoEarleen
1 year agoGwenn
1 year agoRefugia
1 year agoHannah
1 year agoRashida
1 year agoAshleigh
1 year agoTamar
1 year agoJill
1 year agoLuis
1 year agoLeonie
1 year agoAlonzo
1 year agoKiley
1 year agoAndra
1 year ago