Quiz 10 Question 16 of 20

A SOC analyst compares two incidents from last week. Incident A shows an EDR alert for a new scheduled task running a PowerShell command from %APPDATA%. Incident B shows proxy logs with periodic HTTPS beaconing to a newly registered domain. Which finding provides the strongest evidence that both incidents belong to the same adversary campaign?

Select an answer to reveal the explanation.

Motivation