200-201 · Question #59
An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection. Which two pieces of information from the…
The correct answer is B. host IP addresses E. domain names. When investigating outbound callouts made post-infection, the IP addresses of the destination hosts and the domain names contacted by the suspicious file are crucial pieces of information. They provide insight into the external destinations the infected system attempted to…
Question
An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection. Which two pieces of information from the analysis report are needed to investigate the callouts? (Choose two.)
Options
- Asignatures
- Bhost IP addresses
- Cfile size
- Ddropped files
- Edomain names
How the community answered
(32 responses)- A3% (1)
- B78% (25)
- C6% (2)
- D13% (4)
Explanation
When investigating outbound callouts made post-infection, the IP addresses of the destination hosts and the domain names contacted by the suspicious file are crucial pieces of information. They provide insight into the external destinations the infected system attempted to communicate with, aiding in identifying potentially malicious servers, analyzing network traffic, and understanding the scope or impact of the infection. These details are essential for further investigation, monitoring, and implementing necessary security measures.
Topics
Community Discussion
No community discussion yet for this question.