nerdexam
Cisco

200-201 · Question #59

An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection. Which two pieces of information from the…

The correct answer is B. host IP addresses E. domain names. When investigating outbound callouts made post-infection, the IP addresses of the destination hosts and the domain names contacted by the suspicious file are crucial pieces of information. They provide insight into the external destinations the infected system attempted to…

Submitted by weili_xi· Mar 6, 2026Host-Based Analysis

Question

An engineer runs a suspicious file in a sandbox analysis tool to see the outcome. The analysis report shows that outbound callouts were made post infection. Which two pieces of information from the analysis report are needed to investigate the callouts? (Choose two.)

Options

  • Asignatures
  • Bhost IP addresses
  • Cfile size
  • Ddropped files
  • Edomain names

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    78% (25)
  • C
    6% (2)
  • D
    13% (4)

Explanation

When investigating outbound callouts made post-infection, the IP addresses of the destination hosts and the domain names contacted by the suspicious file are crucial pieces of information. They provide insight into the external destinations the infected system attempted to communicate with, aiding in identifying potentially malicious servers, analyzing network traffic, and understanding the scope or impact of the infection. These details are essential for further investigation, monitoring, and implementing necessary security measures.

Topics

#malware analysis#sandbox analysis#network forensics#C2 communication

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice