300-215 · Question #4
A security team received an alert of suspicious activity on a user's Internet browser. The user's anti- virus software indicated that the file attempted to create a fake recycle bin folder and…
The correct answer is B. Analyze the TCP/IP Streams in Cisco Secure Malware Analytics (Threat Grid). C. Evaluate the behavioral indicators in Cisco Secure Malware Analytics (Threat Grid). Cisco Secure Malware Analytics (formerly Threat Grid) enables deep file behavior analysis, including TCP/IP stream analysis and behavioral indicators such as file system activity, process injection, registry changes, and command and control communication. These are essential in…
Question
A security team received an alert of suspicious activity on a user's Internet browser. The user's anti- virus software indicated that the file attempted to create a fake recycle bin folder and connect to an external IP address. Which two actions should be taken by the security analyst with the executable file for further analysis? (Choose two.)
Options
- AEvaluate the process activity in Cisco Umbrella.
- BAnalyze the TCP/IP Streams in Cisco Secure Malware Analytics (Threat Grid).
- CEvaluate the behavioral indicators in Cisco Secure Malware Analytics (Threat Grid).
- DAnalyze the Magic File type in Cisco Umbrella.
- ENetwork Exit Localization in Cisco Secure Malware Analytics (Threat Grid).
How the community answered
(54 responses)- A17% (9)
- B72% (39)
- D7% (4)
- E4% (2)
Explanation
Cisco Secure Malware Analytics (formerly Threat Grid) enables deep file behavior analysis, including TCP/IP stream analysis and behavioral indicators such as file system activity, process injection, registry changes, and command and control communication. These are essential in understanding what the suspicious file does post-execution, especially given the described behavior of creating a fake folder and outbound connection attempts.
Topics
Community Discussion
No community discussion yet for this question.