QuestionQ17

Threat Hunting Outcomes

A SOC team receives a cloud indicator-of-compromise alert through Cisco Secure Endpoint. The alert shows that Microsoft Word tried to launch PowerShell by executing a VBA macro on a user workstation. After further investigation, the team determines that the PowerShell launch was blocked because of the company’s group policies.

Which action must the team take next to mitigate the issue?

Explanation

Because the VBA macro’s attempt to launch PowerShell was blocked by company group policies, the mitigation control is the relevant safeguard to validate. Reviewing the group policies confirms that the blocking configuration is correct and continues to protect endpoints from the attempted execution technique.

Community Discussion

No comments yet. Be the first to start the discussion!