hardMultiple ChoiceObjective-mapped
SSCP The analyst's BEST next step? Practice Question
Exhibit
Refer to the exhibit. Event ID: 4688 Process: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe CommandLine: powershell -EncodedCommand SQBmACgAJABlAG4AdgA6AHUAcwBlAHIAcwBRAHUAYQBsAGkAZgB5ACAALQBjACAAMQApAHsA... (truncated)
What is the analyst's BEST next step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decode the command to analyze
Decoding the encoded PowerShell command will reveal the payload. Option A is premature without understanding the threat. Option B is less helpful. Option D may break legitimate functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Isolate the system
Why it's wrong here
Isolation may be needed after analysis, but first understand the command.
- ✗
Block PowerShell execution
Why it's wrong here
Blocking PowerShell could disrupt legitimate operations; analyze first.
- ✓
Decode the command to analyze
Why this is correct
Decoding allows the analyst to determine if the command is malicious.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan addresses known malware signatures but fails in this scenario because the threat is an active, unknown zero-day exploit that antivirus definitions cannot yet detect. It is tempting because antivirus is a standard first response to suspected infection, and it would be correct if the incident involved a known malicious executable rather than a novel, signatureless attack requiring behavioural analysis or endpoint detection and response (EDR) tools.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.