Question 1
A SOC analyst at a pharmaceutical company is investigating a high-severity alert from their SIEM. The alert triggered on a correlation rule that detects a successful VPN login from an un-recognized IP address followed within two minutes by the execution of powershell.exe -e JABj.... The Base64 encoded string is too long to be fully displayed in the alert summary. What is the analyst's most critical immediate next step to determine the nature of the potential incident?
Answer and explanation
Correct answer: C
The most critical immediate step is to understand what the PowerShell command is attempting to do. Blocking the IP or isolating the host are containment actions that should be taken, but not before gaining context. Without understanding the payload, the analyst cannot determine the scope or severity of the incident. Decoding the Base64 string from the full log entry will reveal the actual commands being executed, providing the necessary intelligence to guide subsequent containment and eradication steps.