QuestionQ73
Incident Response TechniquesA security team receives a notification from a Cisco ESA solution that an employee was sent an advertising email containing an attachment with a .pdf extension. The employee opened the attachment, which seemed to be a blank document. The security analyst finds no clear indicators of compromise, but examines running processes and finds that PowerShell.exe was spawned by CMD.exe, whose grandparent process was AcroRd32.exe. Which two actions should be taken to resolve this issue?
Choose two
- A Upload the .pdf file to Cisco Threat Grid and analyze suspicious activity in depth.
- B No action is required because this behavior is standard for .pdf files.
- C Check the Windows Event Viewer for security logs about the incident.
- D Quarantine this workstation for further investigation, as this event is an indication of suspicious activity.
- E Investigate the reputation of the sender address and temporarily block all communications with this email domain.
Community Discussion