nerdexam
Cisco

200-201 · Question #213

According to the September 2020 threat intelligence feeds a new malware called Egregor was introduced and used in many attacks. Distnbution of Egregor is pnmanly through a Cobalt Strike that has been

The correct answer is B. ransomware attack. The attack described, which involves data exfiltration and threatening public release if payment is not made, is a clear example of a modern ransomware attack, specifically employing a 'double extortion' tactic.

Submitted by marco_it· Mar 6, 2026Security Concepts

Question

According to the September 2020 threat intelligence feeds a new malware called Egregor was introduced and used in many attacks. Distnbution of Egregor is pnmanly through a Cobalt Strike that has been installed on victim's workstations using RDP exploits Malware exfiltrates the victim's data to a command and control server. The data is used to force victims pay or lose it by publicly releasing it. Which type of attack is described?

Options

  • Amalware attack
  • Bransomware attack
  • Cwhale-phishing
  • Dinsider threat

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    82% (31)
  • C
    11% (4)
  • D
    5% (2)

Why each option

The attack described, which involves data exfiltration and threatening public release if payment is not made, is a clear example of a modern ransomware attack, specifically employing a 'double extortion' tactic.

Amalware attack

While Egregor is malware, 'malware attack' is a broad category, and 'ransomware attack' is a more specific and accurate classification given the detailed attack methodology and motivation.

Bransomware attackCorrect

The description details a ransomware attack, characterized by the exfiltration of data and the threat of public release to compel victims to pay a ransom, a common tactic known as double extortion.

Cwhale-phishing

Whale-phishing is a social engineering attack targeting high-value individuals, which is not the primary mechanism described for Egregor's distribution via RDP exploits.

Dinsider threat

An insider threat involves malicious activity by an authorized individual within an organization, which contradicts the external RDP exploits and malware distribution described.

Concept tested: Identifying ransomware characteristics

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/intelligence/ransomware

Topics

#ransomware#malware#data exfiltration#threat intelligence

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice