Quiz 3 Question 17 of 20

Your SIEM alerts on a suspicious PowerShell execution event linked to file hash A1B2C3D4. The hash is confirmed as malicious malware. To identify additional command-and-control infrastructure associated with this specific sample, which action should you take?

Select an answer to reveal the explanation.

Motivation