nerdexam
CompTIA

CS0-003 · Question #331

A security analyst has identified a new malware file that has impacted the organization. The malware is polymorphic and has built-in conditional triggers that require a connection to the internet. The

Sign in or unlock CS0-003 to reveal the answer and full explanation for question #331. The question stem and answer options stay visible for context.

Submitted by noor.lb· Mar 6, 2026Security operations

Question

A security analyst has identified a new malware file that has impacted the organization. The malware is polymorphic and has built-in conditional triggers that require a connection to the internet. The CPU has an idle process of at least 70%. Which of the following best describes how the security analyst can effectively review the malware without compromising the organization's network?

Options

  • AUtilize an RDP session on an unused workstation to evaluate the malware.
  • BDisconnect and utilize an existing infected asset off the network.
  • CCreate a virtual host for testing on the security analyst workstation.
  • DSubscribe to an online service to create a sandbox environment.

Unlock CS0-003 to see the answer

You've previewed enough free CS0-003 questions. Unlock CS0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Malware analysis#Sandbox environment#Polymorphic malware#Secure analysis
Full CS0-003 Practice