🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)61 / 147
Question 61 of 147
A SOC analyst is dispatched to investigate a corporate laptop suspected of running fileless malware. The user reports the machine is still powered on and connected to the network, and threat intel indicates the malware injects into legitimate processes and leaves minimal disk artifacts. To preserve the most relevant evidence for this type of intrusion, what should the analyst prioritize first?
Reviewed for accuracy · Report an issueNext question