nerdexam
EC-Council

312-49V11 · Question #173

A cybersecurity investigator is analyzing a sophisticated malware program that has infiltrated a corporate network. The malware appears to use multiple propagation methods and exploits several…

The correct answer is B. Setting up a controlled malware analysis lab and executing the malware in isolation. To accurately determine malware behavior (persistence, C2, lateral movement, dropped files, registry changes), the investigator should perform dynamic analysis in a controlled, isolated environment (sandbox/lab). This yields high-fidelity behavioral indicators and containment…

Malware Forensics

Question

A cybersecurity investigator is analyzing a sophisticated malware program that has infiltrated a corporate network. The malware appears to use multiple propagation methods and exploits several system vulnerabilities. After capturing a sample of the malware, which of the following steps should the investigator prioritize in order to accurately determine its behavior and prevent further damage?

Options

  • AUsing a signature-based IDS to detect known malicious payloads
  • BSetting up a controlled malware analysis lab and executing the malware in isolation
  • CDeploying an endpoint detection and response solution to oversee endpoint activities
  • DImplementing network flow analysis to monitor data transmission

How the community answered

(25 responses)
  • A
    16% (4)
  • B
    72% (18)
  • C
    8% (2)
  • D
    4% (1)

Explanation

To accurately determine malware behavior (persistence, C2, lateral movement, dropped files, registry changes), the investigator should perform dynamic analysis in a controlled, isolated environment (sandbox/lab). This yields high-fidelity behavioral indicators and containment guidance without risking production systems.

Topics

#malware analysis#sandbox environment#malware behavior#controlled lab

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice