200-201 • Practice Exam 56
Free 200-201 practice exam — 20 questions with explanations. Set 56. No signup required.
A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.