CCOA Incident Detection And Response Practice Question
You are investigating an EDR alert showing suspicious PowerShell execution. You need to identify the parent process that spawned the malicious script. Which tool or view would best allow you to visualize this process tree?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process Tree view
Process tree visualization is a core feature of EDR platforms like Falcon or Defender for Endpoint, allowing analysts to trace execution lineage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Host status dashboard
Why it's wrong here
This provides high-level health metrics, not forensic detail.
- ✗
Network connections tab
Why it's wrong here
This shows external traffic, not process hierarchy.
- ✓
Process Tree view
Why this is correct
The Process Tree visualizes the parent-child relationship of executing processes.
- ✗
Event search logs
Why it's wrong here
Logs provide raw data but lack the immediate visual context of a tree.
About these practice questions
This CCOA question is part of Courseiva's 203-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official ISACA exam blueprint
This CCOA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCOA exam.