350-201(NEW-127Q) · Question #63
An organization had a ransomware event. The engineer working the case discovered an unknown binary file and sent it to the Cisco Secure Malware Analytics for analysis. Which step must the engineer…
The correct answer is A. Examine Malware Analytics report to know more about the file. Option A is correct because once a file has been submitted to Cisco Secure Malware Analytics (formerly Threat Grid), the platform automatically runs the file through its sandboxed environment and generates a detailed behavioral analysis report - examining that report is the…
Question
Options
- AExamine Malware Analytics report to know more about the file.
- BRemove the file and look for similar occurrences using Cisco Orbital.
- CRun an endpoint scan using Cisco Secure Endpoint.
- DAnalyze the file in the Cuckoo sandbox.
How the community answered
(52 responses)- A88% (46)
- B6% (3)
- C4% (2)
- D2% (1)
Explanation
Option A is correct because once a file has been submitted to Cisco Secure Malware Analytics (formerly Threat Grid), the platform automatically runs the file through its sandboxed environment and generates a detailed behavioral analysis report - examining that report is the analysis step. Options B and C are remediation/hunting actions (removing the file, scanning endpoints) that come after you've already understood the threat, not while you're still in the analysis phase. Option D is a trap: Cuckoo is an open-source sandbox, but Cisco Secure Malware Analytics already performs sandboxed detonation internally - submitting the file again to a separate sandbox is redundant and not the intended workflow.
Memory tip: Think of it as a pipeline - Submit → Report → Act. The file was already submitted, so the next logical step is to read the report before taking any action. If the question says "sent to Malware Analytics," your answer is always "examine the Malware Analytics report."
Topics
Community Discussion
No community discussion yet for this question.