QuestionQ94
Forensics Processes
Refer to the exhibit. A company employee receives an email from a customer that contains a Microsoft Word attachment. As soon as the employee opens the attachment, the workstation starts behaving strangely and unusual pop-ups appear. Later that day, another workstation in the same department exhibits the same behavior. The security administrator analyzes the first workstation (Patient 0) in a sandbox environment and identifies several threats. What must the administrator determine next?
- A if Patient 0 still demonstrates suspicious behavior
- B source code of the malicious attachment
- C if the file in Patient 0 is encrypted
- D if Patient 0 tried to connect to another workstation
Community Discussion