Finance analysts report odd PowerShell activity on a workstation that touches ACH files. Which enterprise capability is best suited to investigate and contain that endpoint behavior?
Select an answer to reveal the explanation.
Short Explanation
When PowerShell starts acting weird on a money PC, you want a security camera and remote lock for that box—not a longer password calendar. EDR/XDR digs into the process trail and can isolate the host.
Full Explanation
EDR and XDR platforms collect rich endpoint telemetry, support investigation of suspicious scripting such as PowerShell, and enable response actions like isolation. Physical visitor logs, password-expiry tweaks, and badge schedules do not analyze or contain malicious endpoint process activity.