nerdexam
Cisco

350-201(NEW-127Q) · Question #100

Refer to the exhibit. A system administrator has recently submitted a file for malware analysis to Cisco Secure Malware Analytics. According to this Cisco Secure Malware Analytics report, what is…

The correct answer is C. A Domain Flagged by Cisco Umbrella Downloaded APE file. Option C is correct because it represents a behavioral indicator tied to verified threat intelligence: during sandbox analysis, the file reached out to a domain already flagged as malicious by Cisco Umbrella (a DNS-layer security service with authoritative reputation data) and…

Threat Analysis and Detection

Question

Refer to the exhibit. A system administrator has recently submitted a file for malware analysis to Cisco Secure Malware Analytics. According to this Cisco Secure Malware Analytics report, what is the indicator of compromise that will prevent this file form being categorized as a false positive?

Options

  • AArtifacts flagged malicious by Antivirus Service
  • BEmotet Malware Detected
  • CA Domain Flagged by Cisco Umbrella Downloaded APE file
  • DDocument Submission (Contacted Domain Flagged by Cisco Umbrella

How the community answered

(17 responses)
  • A
    29% (5)
  • B
    12% (2)
  • C
    53% (9)
  • D
    6% (1)

Explanation

Option C is correct because it represents a behavioral indicator tied to verified threat intelligence: during sandbox analysis, the file reached out to a domain already flagged as malicious by Cisco Umbrella (a DNS-layer security service with authoritative reputation data) and used it to download an additional payload (APE file). This chained network behavior - calling home to a known-bad domain to pull down more malware - is strong, corroborated evidence of malicious intent that rules out false positive classification.

Why the distractors are wrong:

  • A is wrong because antivirus flagging is itself a common source of false positives; signature-based AV detections alone lack the behavioral specificity needed for confirmation.
  • B is wrong because "Emotet Malware Detected" is a classification label or detection name, not a discrete indicator of compromise - labels can be applied incorrectly without underlying behavioral proof.
  • D is wrong because "Document Submission" describes the file type submitted, not an IoC. While it also references Umbrella, the answer conflates the submission method with the actual compromise indicator.

Memory tip: Think of it as a two-key lock - Cisco Umbrella already flagged the domain, and the file actively called it to download more code. Two independent threat signals aligning (reputation + live behavior) is what locks out the false positive verdict. When you see "Umbrella-flagged domain + downloaded payload," that's your confirmed IoC.

Topics

#Malware Analysis#Indicators of Compromise#Cisco Secure Malware Analytics#Threat Intelligence

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice