CS0-003 · Question #362
SIMULATION A company recently experienced a security incident. The security team has determined a user clicked on a link embedded in a phishing email that was sent to the entire company. The link…
This simulation requires candidates to perform a multi-step incident response analysis by correlating artifacts across multiple log sources (firewall logs, file integrity monitoring reports, malware domain lists, vulnerability scan reports, and phishing emails) to identify the…
Question
SIMULATION A company recently experienced a security incident. The security team has determined a user clicked on a link embedded in a phishing email that was sent to the entire company. The link resulted in a malware download, which was subsequently installed and run. INSTRUCTIONS Part 1 Review the artifacts associated with the security Incident. Identify the name of the malware, the malicious IP address, and the date and time when the malware executable entered the organization. Part 2 Review the kill chain items and select an appropriate control for each that would improve the security posture of the organization and would have helped to prevent this incident from occurring. Each control may only be used once, and not all controls will be used. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Firewall log:
File integrity Monitoring Report:
Malware domain list:
Vulnerability Scan Report:
Phishing Email:
Answer:
Kill Chain Item:
Phishing email - Email filtering Active links - VPN Malicious website access - IP blocklist Malware download - Firewall file type filter Malware install - Restricted local user permissions Malware execution - Updated antivirus File encryption - Backups Identify the following:
Malicious executable - Payroll.xlsx Malicious IP Address - 81.161.63.103 Date/time malware entered organization- 1 Dec 2019 14:03:19
Exhibits
Explanation
This simulation requires candidates to perform a multi-step incident response analysis by correlating artifacts across multiple log sources (firewall logs, file integrity monitoring reports, malware domain lists, vulnerability scan reports, and phishing emails) to identify the malware name, malicious IP address, and entry timestamp. The correct approach involves cross-referencing the firewall log for the initial connection alert, the file integrity monitoring report for when the executable was written to disk, and the malware domain list to confirm the malicious IP - demonstrating real-world SOC analyst workflow. For Part 2, kill chain controls must be mapped appropriately (e.g., email filtering for the phishing delivery stage, web proxy/DNS filtering for the exploitation stage, endpoint protection for the installation stage) using each control only once, reflecting defense-in-depth principles tied directly to the MITRE ATT&CK or Lockheed Martin Kill Chain framework.
Topics
Community Discussion
No community discussion yet for this question.








