Quiz 2 Question 16 of 20

A SOC analyst reviewing SIEM output sees three low-confidence alerts for the same workstation: an unusual login location, a PowerShell command with encoded arguments, and DNS queries to a newly registered domain. No single alert is high severity. What should the analyst do first to determine malicious activity?

Select an answer to reveal the explanation.

Motivation