ISC2 CC • Practice Test 2 — 30 Questions
Free ISC2 CC practice test 2 — 30 questions with explanations. No signup required.
A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
30 questions · instant feedback and full explanations after every question.