Quiz 12 Question 17 of 20

After ransomware-like activity, a SOC analyst has forensic disk images from several workstations and a known malware string from a sample. The analyst needs to locate every file containing that string across all images before deciding containment. Which incident response technique should be used first?

Select an answer to reveal the explanation.

Motivation