Valid SY0-601 Dumps shared by ExamDiscuss.com for Helping Passing SY0-601 Exam! ExamDiscuss.com now offer the newest SY0-601 exam dumps, the ExamDiscuss.com SY0-601 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com SY0-601 dumps with Test Engine here:
A security analyst is investigating an incident to determine what an attacker was able to do on a compromised laptop. The analyst reviews the following SIEM log: Which of the following describes the method that was used to compromise the laptop?
Correct Answer: B
Based on the provided information, it appears that the attacker was able to bypass application whitelisting by emailing a spreadsheet attachment with an embedded PowerShell in the file, as indicated by the "New Process" event with the process name "lat.ps1" and the "Creator Process Name" of "powershell.exe". This suggests that the attacker was able to execute a PowerShell script to run malicious code.