🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)57 / 147
Question 57 of 147
During an investigation, a SOC analyst reviews EDR telemetry from a compromised workstation. The analyst notes two distinct findings: (1) a specific SHA-256 hash matching a file quarantined on the host, and (2) a PowerShell process spawning from a Word document and immediately establishing an encoded outbound connection while attempting to disable logging. The analyst must classify these findings correctly to inform detection strategy. How should the analyst categorize the two findings?
Reviewed for accuracy · Report an issueNext question