🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)139 / 145
Question 139 of 145

While reviewing Windows Security event logs on a workstation, an analyst finds Event ID 4688 showing that 'cmd.exe' launched 'powershell.exe -enc <base64 string>' with the parent process listed as 'winword.exe'. What does this log entry most directly indicate the analyst should investigate?

Reviewed for accuracy · Report an issueNext question