nerdexam
EC-Council

312-50V12 · Question #255

A security analyst is preparing to analyze a potentially malicious program believed to have infiltrated an organization's network. To ensure the safety and integrity of the production environment, the

The correct answer is B. Store the potentially malicious program on an external medium, such as a CD-ROM.. To safely analyze a potentially malicious program using an isolated sheep dip computer, the crucial preliminary step is to transfer the program via an external, non-networked medium.

Submitted by kev92· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

A security analyst is preparing to analyze a potentially malicious program believed to have infiltrated an organization's network. To ensure the safety and integrity of the production environment, the analyst decided to use a sheep dip computer for the analysis. Before initiating the analysis, what key step should the analyst take?

Options

  • AInstall the potentially malicious program on the sheep dip computer.
  • BStore the potentially malicious program on an external medium, such as a CD-ROM.
  • CRun the potentially malicious program on the sheep dip computer to determine its behavior.
  • DConnect the sheep dip computer to the organization's internal network.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    89% (31)
  • C
    6% (2)
  • D
    3% (1)

Why each option

To safely analyze a potentially malicious program using an isolated sheep dip computer, the crucial preliminary step is to transfer the program via an external, non-networked medium.

AInstall the potentially malicious program on the sheep dip computer.

Installing the program is a part of the analysis process itself, which occurs after the program has been safely transferred to the sheep dip computer.

BStore the potentially malicious program on an external medium, such as a CD-ROM.Correct

Transferring the malicious program via an external medium like a CD-ROM is a critical preliminary step to safely introduce the program into an isolated sheep dip environment without compromising the organization's production network. This method maintains the air-gapped nature of the sheep dip system, ensuring the program cannot spread through network connections during transfer.

CRun the potentially malicious program on the sheep dip computer to determine its behavior.

Running the program is the core action of the analysis phase, not a prerequisite step taken before initiating the analysis.

DConnect the sheep dip computer to the organization's internal network.

Connecting the sheep dip computer to the internal network would defeat its purpose of being an isolated environment for safe malware analysis and risk infecting the production network.

Concept tested: Secure malware transfer to isolated analysis environment

Topics

#Malware analysis#Sheep dip computer#Sandbox#Security best practices

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice