Quiz 2 Question 15 of 20

An EDR alert shows a suspicious PowerShell command launched under WINWORD.EXE. Which action uses process lineage to determine whether the activity is malicious?

Select an answer to reveal the explanation.

Motivation