300-215 · Question #23
Refer to the exhibit. Which determination should be made by a security analyst?
The correct answer is D. An email was sent with an attachment named "Final Report.doc.exe". The XML structure shows that: The file name starts with: "Final Report" The file extension equals: "doc.exe" Together, this forms "Final Report.doc.exe" -- a known double-extension technique used to disguise executables as benign documents. This is a red flag in email…
Question
Refer to the exhibit. Which determination should be made by a security analyst?
Exhibit
Options
- AAn email was sent with an attachment named "Grades.doc.exe".
- BAn email was sent with an attachment named "Grades.doc".
- CAn email was sent with an attachment named "Final Report.doc".
- DAn email was sent with an attachment named "Final Report.doc.exe".
How the community answered
(19 responses)- A11% (2)
- B5% (1)
- C5% (1)
- D79% (15)
Explanation
The XML structure shows that: The file name starts with: "Final Report" The file extension equals: "doc.exe" Together, this forms "Final Report.doc.exe" -- a known double-extension technique used to disguise executables as benign documents. This is a red flag in email forensics, commonly linked to malware distribution, and explicitly covered in the Cisco CyberOps study material as a typical evasion method for malicious attachments.
Topics
Community Discussion
No community discussion yet for this question.
