300-215 · Question #20
A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file's…
The correct answer is C. Antivirus solution. If IPS and SIEM logs do not give enough insight into a file's behavior, the next logical step is to review the Antivirus solution logs. These logs often provide detailed behavior analytics such as: - File actions and access patterns - Registry modifications - File execution…
Question
A scanner detected a malware-infected file on an endpoint that is attempting to beacon to an external site. An analyst has reviewed the IPS and SIEM logs but is unable to identify the file's behavior. Which logs should be reviewed next to evaluate this file further?
Options
- Aemail security appliance
- BDNS server
- CAntivirus solution
- Dnetwork device
How the community answered
(51 responses)- A6% (3)
- B4% (2)
- C78% (40)
- D12% (6)
Explanation
If IPS and SIEM logs do not give enough insight into a file's behavior, the next logical step is to review the Antivirus solution logs. These logs often provide detailed behavior analytics such as: - File actions and access patterns - Registry modifications - File execution history The Cisco CyberOps guide emphasizes AV logs as critical forensic artifacts for understanding endpoint-based infections, especially when beaconing or suspicious activity is suspected.
Topics
Community Discussion
No community discussion yet for this question.