nerdexam
Cisco

350-201 · Question #132

Refer to the exhibit. An engineer is performing static analysis of a file received and reported by a user. Which risk is indicated in this STIX?

The correct answer is D. The file is redirecting users to a website that is determining users' geographic location. The STIX observable indicators in the file point to network behavior consistent with determining the victim's geographic location, not ransomware, credential theft, or privilege escalation.

Techniques

Question

Refer to the exhibit. An engineer is performing static analysis of a file received and reported by a user. Which risk is indicated in this STIX?

Exhibit

350-201 question #132 exhibit

Options

  • AThe file is redirecting users to a website that requests privilege escalations from the user.
  • BThe file is redirecting users to the website that is downloading ransomware to encrypt files.
  • CThe file is redirecting users to a website that harvests cookies and stored account information.
  • DThe file is redirecting users to a website that is determining users' geographic location.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    84% (21)

Why each option

The STIX observable indicators in the file point to network behavior consistent with determining the victim's geographic location, not ransomware, credential theft, or privilege escalation.

AThe file is redirecting users to a website that requests privilege escalations from the user.

Privilege escalation activity would be represented in STIX by process observables, system call patterns, or references to local exploit tools targeting OS permission boundaries, which are absent here.

BThe file is redirecting users to the website that is downloading ransomware to encrypt files.

Ransomware delivery would appear as STIX indicators referencing file encryption observables, known ransomware C2 domains, or ransom note file artifacts, none of which are indicated.

CThe file is redirecting users to a website that harvests cookies and stored account information.

Cookie and credential harvesting would surface as STIX observables targeting browser storage paths or network exfiltration of authentication tokens, which do not match the indicators shown.

DThe file is redirecting users to a website that is determining users' geographic location.Correct

STIX (Structured Threat Intelligence eXpression) encodes machine-readable threat indicators including network observables, URLs, and behavioral patterns. The indicators present in this STIX object reference connections to geolocation lookup services or APIs, meaning the redirected site's purpose is to identify and record the victim's physical location rather than perform any destructive or credential-stealing action.

Concept tested: STIX threat intelligence indicator analysis

Source: https://oasis-open.github.io/cti-documentation/stix/intro

Topics

#STIX#static analysis#threat intelligence#malware analysis

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice