Cisco Related Exams
300-215 Exam
During a routine inspection of system logs, a security analyst notices an entry where Microsoft Word initiated a PowerShell command with encoded arguments. Given that the user's role does not involve scripting or advanced document processing, which action should the analyst take to analyze this output for potential indicators of compromise?

Refer to the exhibit.

Which two determinations should be made about the attack from the Apache access logs? (Choose two.)