🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)57 / 145
Question 57 of 145

A security analyst reviewing endpoint telemetry notices that winword.exe spawned powershell.exe, which then executed a heavily encoded command that downloaded and ran additional code directly in memory. No malicious file was ever written to the disk, so the file-based antivirus scan came back clean. Which type of endpoint-based attack does this behavior BEST describe?

Reviewed for accuracy · Report an issueNext question