nerdexam
Cisco

300-710 · Question #285

A network administrator is reviewing a monthly advanced malware risk report and notices a host that is listed as CnC Connected. Where must the administrator look within Cisco FMC to further…

The correct answer is A. Analysis > Hosts > Indications of Compromise. To investigate a host identified as "CnC Connected" in Cisco FMC for potential malware infection, the administrator should check the "Indications of Compromise" section.

Management and Troubleshooting

Question

A network administrator is reviewing a monthly advanced malware risk report and notices a host that is listed as CnC Connected. Where must the administrator look within Cisco FMC to further determine if this host is infected with malware?

Options

  • AAnalysis > Hosts > Indications of Compromise
  • BAnalysis > Hosts > Host Attributes
  • CAnalysis > Files > Malware Events
  • DAnalysis > Files > Network File Trajectory

How the community answered

(20 responses)
  • A
    70% (14)
  • B
    15% (3)
  • C
    5% (1)
  • D
    10% (2)

Why each option

To investigate a host identified as "CnC Connected" in Cisco FMC for potential malware infection, the administrator should check the "Indications of Compromise" section.

AAnalysis > Hosts > Indications of CompromiseCorrect

In Cisco FMC, the "Analysis > Hosts > Indications of Compromise" page provides a comprehensive view of suspicious activities and potential compromises detected on a host, including Command and Control (CnC) connections, which directly point to potential malware infection. This dashboard aggregates various security events into clear indicators.

BAnalysis > Hosts > Host Attributes

Host Attributes provides general information about a host, such as operating system, services, and vulnerabilities, but not specific indications of compromise like CnC activity.

CAnalysis > Files > Malware Events

Malware Events specifically lists detected malware files and their dispositions, but Indications of Compromise provides a broader context for the host's overall compromise status.

DAnalysis > Files > Network File Trajectory

Network File Trajectory tracks the path of files across the network, showing where a file originated, where it went, and its disposition, which is useful for file analysis but not the primary place to confirm host compromise status based on CnC.

Concept tested: FMC malware analysis and host compromise identification

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/fpmc-intrusion.html#concept_D8E53EC8663E480EAA84620A07B37B24

Topics

#Cisco FMC#Malware Analysis#Command and Control (CnC)#Host Compromise

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice