GCFA Enterprise Environment Incident Response • Set 4
GCFA Enterprise Environment Incident Response Practice Test 4 — 15 questions with explanations. Free, no signup.
A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.