Quiz 5 Question 2 of 20

A SOC analyst receives a high-severity EDR alert showing file encryption behavior on a production file server. The analyst wants to improve response efficiency. Which action best supports efficient incident handling?

Select an answer to reveal the explanation.

Motivation