Quiz 11 Question 3 of 20

An EDR alert shows encoded PowerShell execution on a host. A scanner later flags an unrelated app with CVSS 9.8. When prioritizing detection and response actions for the active incident, which source should guide the analyst?

Select an answer to reveal the explanation.

Motivation