312-49V11 · Question #173
A cybersecurity investigator is analyzing a sophisticated malware program that has infiltrated a corporate network. The malware appears to use multiple propagation methods and exploits several…
The correct answer is B. Setting up a controlled malware analysis lab and executing the malware in isolation. To accurately determine malware behavior (persistence, C2, lateral movement, dropped files, registry changes), the investigator should perform dynamic analysis in a controlled, isolated environment (sandbox/lab). This yields high-fidelity behavioral indicators and containment…
Question
A cybersecurity investigator is analyzing a sophisticated malware program that has infiltrated a corporate network. The malware appears to use multiple propagation methods and exploits several system vulnerabilities. After capturing a sample of the malware, which of the following steps should the investigator prioritize in order to accurately determine its behavior and prevent further damage?
Options
- AUsing a signature-based IDS to detect known malicious payloads
- BSetting up a controlled malware analysis lab and executing the malware in isolation
- CDeploying an endpoint detection and response solution to oversee endpoint activities
- DImplementing network flow analysis to monitor data transmission
How the community answered
(25 responses)- A16% (4)
- B72% (18)
- C8% (2)
- D4% (1)
Explanation
To accurately determine malware behavior (persistence, C2, lateral movement, dropped files, registry changes), the investigator should perform dynamic analysis in a controlled, isolated environment (sandbox/lab). This yields high-fidelity behavioral indicators and containment guidance without risking production systems.
Topics
Community Discussion
No community discussion yet for this question.