🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)116 / 147
Question 116 of 147
During an active investigation, a SOC analyst reviews EDR telemetry from a workstation. The analyst observes that a Word process spawned PowerShell, which then invoked WMI to enumerate remote hosts and initiated encrypted outbound connections to an unfamiliar host — all within 90 seconds, before any file hashes or known-malicious domains were matched. Management wants detection engineering to build a rule that catches this class of activity earlier next time. Which type of indicator should the analyst prioritize when authoring the new detection?
Reviewed for accuracy · Report an issueNext question