300-710 · Question #285
A network administrator is reviewing a monthly advanced malware risk report and notices a host that is listed as CnC Connected. Where must the administrator look within Cisco FMC to further…
The correct answer is A. Analysis > Hosts > Indications of Compromise. To investigate a host identified as "CnC Connected" in Cisco FMC for potential malware infection, the administrator should check the "Indications of Compromise" section.
Question
A network administrator is reviewing a monthly advanced malware risk report and notices a host that is listed as CnC Connected. Where must the administrator look within Cisco FMC to further determine if this host is infected with malware?
Options
- AAnalysis > Hosts > Indications of Compromise
- BAnalysis > Hosts > Host Attributes
- CAnalysis > Files > Malware Events
- DAnalysis > Files > Network File Trajectory
How the community answered
(20 responses)- A70% (14)
- B15% (3)
- C5% (1)
- D10% (2)
Why each option
To investigate a host identified as "CnC Connected" in Cisco FMC for potential malware infection, the administrator should check the "Indications of Compromise" section.
In Cisco FMC, the "Analysis > Hosts > Indications of Compromise" page provides a comprehensive view of suspicious activities and potential compromises detected on a host, including Command and Control (CnC) connections, which directly point to potential malware infection. This dashboard aggregates various security events into clear indicators.
Host Attributes provides general information about a host, such as operating system, services, and vulnerabilities, but not specific indications of compromise like CnC activity.
Malware Events specifically lists detected malware files and their dispositions, but Indications of Compromise provides a broader context for the host's overall compromise status.
Network File Trajectory tracks the path of files across the network, showing where a file originated, where it went, and its disposition, which is useful for file analysis but not the primary place to confirm host compromise status based on CnC.
Concept tested: FMC malware analysis and host compromise identification
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/fpmc-intrusion.html#concept_D8E53EC8663E480EAA84620A07B37B24
Topics
Community Discussion
No community discussion yet for this question.