An EDR process tree for a compromised workstation shows OUTLOOK.EXE launching POWERSHELL.EXE, which then launches MSHTA.EXE to download a payload. The analyst must identify the initial execution vector for the incident report. Which relationship best explains how the malicious activity began?
Select an answer to reveal the explanation.
Short Explanation
Think of the process tree like a family photo: the child action matters, but you need the parent that lit the fuse. Here, PowerShell and mshta are downstream, while Outlook is the first suspicious parent. You report Outlook spawning PowerShell as the initial execution, not the later child activity you'd be tempted to chase.
Full Explanation
In a process tree, each line shows a parent process creating a child, so the analyst reconstructs the execution lineage from the earliest suspicious parent-child relationship forward. Here, OUTLOOK.EXE created POWERSHELL.EXE, and that PowerShell process later created MSHTA.EXE to fetch a payload. The initial execution vector is therefore the parent-child relationship in which Outlook launched PowerShell, because that is the first step that gave the attacker a script interpreter on the host. PowerShell spawning mshta.exe describes a later child action: it shows how the download occurred, but it assumes PowerShell was already present, so it cannot be the starting point. Explorer.exe spawning a scheduled task is a persistence or scheduling pattern, not the observed email-client execution chain, and no scheduled task appears in the tree. Winword.exe spawning PowerShell.exe would be a strong initial execution answer only if a document macro had launched the shell, but the tree identifies Outlook as the parent, not Word. Exam caveat: CompTIA expects you to read the displayed parent-child order and avoid inferring a macro from the email context alone. Operational check: export the EDR process tree, hash and timestamp each process, then correlate Outlook command lines with message metadata before declaring initial execution.