350-201(NEW-127Q) · Question #100
Refer to the exhibit. A system administrator has recently submitted a file for malware analysis to Cisco Secure Malware Analytics. According to this Cisco Secure Malware Analytics report, what is…
The correct answer is C. A Domain Flagged by Cisco Umbrella Downloaded APE file. Option C is correct because it represents a behavioral indicator tied to verified threat intelligence: during sandbox analysis, the file reached out to a domain already flagged as malicious by Cisco Umbrella (a DNS-layer security service with authoritative reputation data) and…
Question
Options
- AArtifacts flagged malicious by Antivirus Service
- BEmotet Malware Detected
- CA Domain Flagged by Cisco Umbrella Downloaded APE file
- DDocument Submission (Contacted Domain Flagged by Cisco Umbrella
How the community answered
(17 responses)- A29% (5)
- B12% (2)
- C53% (9)
- D6% (1)
Explanation
Option C is correct because it represents a behavioral indicator tied to verified threat intelligence: during sandbox analysis, the file reached out to a domain already flagged as malicious by Cisco Umbrella (a DNS-layer security service with authoritative reputation data) and used it to download an additional payload (APE file). This chained network behavior - calling home to a known-bad domain to pull down more malware - is strong, corroborated evidence of malicious intent that rules out false positive classification.
Why the distractors are wrong:
- A is wrong because antivirus flagging is itself a common source of false positives; signature-based AV detections alone lack the behavioral specificity needed for confirmation.
- B is wrong because "Emotet Malware Detected" is a classification label or detection name, not a discrete indicator of compromise - labels can be applied incorrectly without underlying behavioral proof.
- D is wrong because "Document Submission" describes the file type submitted, not an IoC. While it also references Umbrella, the answer conflates the submission method with the actual compromise indicator.
Memory tip: Think of it as a two-key lock - Cisco Umbrella already flagged the domain, and the file actively called it to download more code. Two independent threat signals aligning (reputation + live behavior) is what locks out the false positive verdict. When you see "Umbrella-flagged domain + downloaded payload," that's your confirmed IoC.
Topics
Community Discussion
No community discussion yet for this question.