Cisco Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) 300-215 Question # 18 Topic 2 Discussion

Cisco Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) 300-215 Question # 18 Topic 2 Discussion

300-215 Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

Refer to the exhibit.

300-215 Question 18

An alert came with a potentially suspicious activity from a machine in HR department. Which two IOCs should the security analyst flag? (Choose two.)


A.

powershell.exe used on HR machine


B.

cmd.exe executing from \Device\HarddiskVolume3\


C.

WScript.exe initiated by powershell.exe


D.

cmd.exe starting powershell.exe with Base64 conversion


E.

WScript.exe acting as a parent of cmd.exe


Get Premium 300-215 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.