300-215 · Question #136
A cybersecurity analyst must evaluate files from an endpoint in an enterprise network. The antivirus software on the endpoint flagged a suspicious file during a routine scan. On initial evaluation, th
The correct answer is D. Submit the file to a threat intelligence platform for further analysis and to identify potential IOCs.. Because the sample shows suspicious behavior but lacks known signature matches, the next step is to submit it to a threat intelligence/malware analysis platform to obtain deeper verdicting and extract actionable indicators (hashes, domains/IPs, file/registry artifacts, behavioral
Question
A cybersecurity analyst must evaluate files from an endpoint in an enterprise network. The antivirus software on the endpoint flagged a suspicious file during a routine scan. On initial evaluation, the file did not match any known signatures in the antivirus database, but exhibited unusual network behavior during dynamic analysis. Which step should the analyst take next?
Options
- AInstall different antivirus software on the endpoint and perform another deep scan of affected
- BDelete the file immediately from the endpoint to prevent the potential spread of malware.
- CFlag the file as a potential false positive due to not matching any known malware signatures.
- DSubmit the file to a threat intelligence platform for further analysis and to identify potential IOCs.
How the community answered
(30 responses)- A3% (1)
- B3% (1)
- C13% (4)
- D80% (24)
Explanation
Because the sample shows suspicious behavior but lacks known signature matches, the next step is to submit it to a threat intelligence/malware analysis platform to obtain deeper verdicting and extract actionable indicators (hashes, domains/IPs, file/registry artifacts, behavioral IOCs). This enables enterprise-wide hunting, correlation, and improved detections/blocks based on confirmed intelligence rather than assumptions.
Topics
Community Discussion
No community discussion yet for this question.