After suspected malware on a clerk PC, which telemetry best answers which process spawned and which files were written?
Select an answer to reveal the explanation.
Short Explanation
The firewall saw cars on the highway; it did not see who opened the filing cabinet. Process creation and file writes live on the clerk PC—EDR and endpoint logs, not perimeter denies or pump-station gauges.
Full Explanation
Host-process questions require endpoint telemetry: EDR or OS process-creation and file-write events from the clerk workstation. Perimeter firewall logs may show related egress but lack process and file fields. Website CMS history and OT historian values are the wrong defense systems for this question. In Splunk ES, those endpoint events typically land in Endpoint or Malware models once CIM-mapped.