ISC2 CC • Practice Test 4
Free ISC2 CC practice test — 10 questions with explanations. Set 4. No signup required.
A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.