Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco Exam 300-215 Topic 10 Question 66 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 66
Topic #: 10
[All 300-215 Questions]

An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Buck
2 hours ago
Ah, the age-old question: 'To open or not to open?' I say, better safe than sorry. Contain that threat, my friend!
upvoted 0 times
...
Tequila
5 days ago
Ooh, an empty Word doc spawning PowerShell? Sounds like a classic case of 'Looks can be deceiving.' Gotta go with option C on this one.
upvoted 0 times
...
Earleen
8 days ago
Threat intelligence, huh? I bet the file has some juicy malware that'll make the hackers laugh all the way to the bank. Better contain this before it spreads!
upvoted 0 times
...
Rashida
9 days ago
Hmm, standard behavior of Word macros? I think not. Something fishy is going on here. Better investigate further!
upvoted 0 times
...
Ashleigh
14 days ago
C'mon, if PowerShell is involved, it's gotta be bad news! Contain that threat, my friend!
upvoted 0 times
...
Alonzo
18 days ago
I believe containing the threat for further analysis is also a good idea. We need to be cautious.
upvoted 0 times
...
Kiley
21 days ago
I agree with Andra. It's important to determine if the file is malicious.
upvoted 0 times
...
Andra
23 days ago
I think the engineer should upload the file signature to threat intelligence tools.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77