NSE6_EDR_AD-7.0 practice question 6 of 10

During a forensics investigation of a detected ransomware incident on an endpoint, you review the timeline of events in the FortiEDR forensics module…

Choose your answer, then check it against the explanation.

During a forensics investigation of a detected ransomware incident on an endpoint, you review the timeline of events in the FortiEDR forensics module and identify that a legitimate user account executed a suspicious PowerShell script that began encrypting files 10 minutes later. You want to understand how the script was delivered and executed. Which forensics analysis feature should you use to trace the execution chain and identify the parent process that launched the malicious PowerShell command?
Answer options
Question 6 of 10

Keep practicing

Take the free NSE6_EDR_AD-7.0 practice test

Ten exam-style questions with answers and explanations, plus the exam facts and study guides.

Start the free practice test

More questions

Other NSE6_EDR_AD-7.0 practice questions

Scroll to Top