350-201 · Question #44
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a low prevalence file to the Threat Grid analysis engine for further analysis…
The correct answer is C. The prioritized behavioral indicators of compromise justify the execution of the "ransomware". This question tests interpretation of a Cisco Threat Grid behavioral analysis report, specifically whether the behavioral indicators observed are sufficient to classify a file as ransomware.
Question
Refer to the exhibit. Cisco Advanced Malware Protection installed on an end-user desktop has automatically submitted a low prevalence file to the Threat Grid analysis engine for further analysis. What should be concluded from this report?
Exhibit
Options
- AThe prioritized behavioral indicators of compromise do not justify the execution of the
- BThe prioritized behavioral indicators of compromise do not justify the execution of the
- CThe prioritized behavioral indicators of compromise justify the execution of the "ransomware"
- DThe prioritized behavioral indicators of compromise justify the execution of the "ransomware"
How the community answered
(53 responses)- A17% (9)
- B4% (2)
- C70% (37)
- D9% (5)
Why each option
This question tests interpretation of a Cisco Threat Grid behavioral analysis report, specifically whether the behavioral indicators observed are sufficient to classify a file as ransomware.
This choice states the BIoCs do not justify the ransomware classification, which contradicts the exhibit data showing sufficient behavioral evidence to trigger that verdict.
This is a duplicate of choice A and is equally incorrect for the same reason - the exhibit's BIoC data supports, not refutes, the ransomware classification.
Cisco Threat Grid scores files by analyzing behavioral indicators of compromise (BIoCs) observed during dynamic sandbox execution. When the aggregated BIoC scores and observed behaviors - such as file encryption, shadow copy deletion, or registry modifications - meet the threshold, Threat Grid assigns a high-confidence 'ransomware' verdict. The exhibit shows BIoC evidence strong enough to justify that classification.
While D also references the ransomware classification being justified, C is the correct selection per the answer key; D likely differs in a detail visible in the full exhibit (such as a specific threat score threshold or label) that distinguishes it from C.
Concept tested: Cisco Threat Grid behavioral indicator analysis for malware classification
Source: https://www.cisco.com/c/en/us/products/security/threat-grid/index.html
Topics
Community Discussion
No community discussion yet for this question.
