Courseiva

SY0-701

Study mode — explanations shown

1

Security Operations

easy

Based on the exhibit, what should the analyst do next to limit the impact of the suspected compromise?

Exhibit

EDR Alert Summary
Host: FIN-LT-22
Severity: High
Detection: Suspicious PowerShell with encoded command
Parent Process: winword.exe
Network Activity: outbound connection to 203.0.113.77:4444
User Note: 'The laptop is running very slowly and pop-ups started after opening an attachment.'
0 of 180 answered