1
Security Operations
easy
Based on the exhibit, what should the analyst do next to limit the impact of the suspected compromise?
Exhibit
EDR Alert Summary Host: FIN-LT-22 Severity: High Detection: Suspicious PowerShell with encoded command Parent Process: winword.exe Network Activity: outbound connection to 203.0.113.77:4444 User Note: 'The laptop is running very slowly and pop-ups started after opening an attachment.'