🔥 3-day streak
Cisco CCNP Security SCOR (350-701)115 / 146
Question 115 of 146
An incident responder using Cisco Secure Endpoint sees that a suspicious executable was detected on a finance workstation. The responder needs to determine exactly which parent process launched the file, what files it created afterward, and the sequence of activity on that single host to identify the root cause of the compromise. Which Secure Endpoint feature should the responder use?
Reviewed for accuracy · Report an issueNext question