Quiz 12 Question 9 of 20

An EDR alert shows PowerShell spawning from an unusual path with no file on disk, and the endpoint is suspected of fileless malware. The analyst must collect evidence before containment could destroy volatile state. What should be captured first?

Select an answer to reveal the explanation.

Motivation