Quiz 2 Question 7 of 20

An EDR alert shows WINWORD.EXE spawning powershell.exe with a base64-encoded command, but a file integrity scan finds no malicious executable on disk. Which finding most reliably supports a fileless malware hypothesis?

Select an answer to reveal the explanation.

Motivation