350-201(NEW-127Q) · Question #38
An engineer is conducting a forensic investigation on a host system in the company network. The system was compromised by an advanced persistent threat group. The engineer identifies that the host…
The correct answer is C. Detection and Analysis. Detection and Analysis (option C) is correct because the engineer is actively performing forensic investigation to understand what happened - identifying the C2 communication method, custom encryption, and steganographic data exfiltration. This phase is defined by discovering…
Question
Options
- APreparation
- BContainment, Eradication, and Recovery
- CDetection and Analysis
- DPost-Incident Activity
How the community answered
(40 responses)- A3% (1)
- B5% (2)
- C93% (37)
Explanation
Detection and Analysis (option C) is correct because the engineer is actively performing forensic investigation to understand what happened - identifying the C2 communication method, custom encryption, and steganographic data exfiltration. This phase is defined by discovering the scope, nature, and mechanisms of an attack, which is exactly what reverse-engineering threat behavior and analyzing IOCs represents.
Why the distractors are wrong:
- A (Preparation) happens before any incident - it covers building response plans, training teams, and staging tools. No active threat is present yet.
- B (Containment, Eradication, and Recovery) comes after you understand the attack - it's about isolating systems, removing malware, and restoring operations. The engineer isn't doing that here.
- D (Post-Incident Activity) is the lessons-learned phase that occurs after the incident is fully resolved, not while forensic work is still underway.
Memory tip: Think of Detection and Analysis as the "detective work" phase - if the engineer is still asking how and what, they're in this stage. Once they switch to fixing it, they've moved to Containment/Eradication/Recovery.
Topics
Community Discussion
No community discussion yet for this question.