nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #72

A Security Operations Center (SOC) is attempting to proactively identify and defend against an evolving spear-phishing campaign that uses novel techniques to deliver custom-built malware. The campaign

The correct answer is B. Submitting all suspicious email attachments to WildFire for immediate dynamic analysis and. This question demands a comprehensive and actionable defense against a sophisticated, evolving threat. Option B combines the strengths of WildFire for rapid, automated technical analysis of new malware variants (generating signatures for NGFWs) with the strategic and tactical int

Threat Intelligence and Analysis

Question

A Security Operations Center (SOC) is attempting to proactively identify and defend against an evolving spear-phishing campaign that uses novel techniques to deliver custom-built malware. The campaign appears to be sponsored by a nation-state. The SOC has access to WildFire, Unit 42 threat intelligence, and regularly queries VirusTotal. To build a robust defense strategy that includes both technical indicators and contextual understanding of the adversary, which of the following actions or integrations would provide the MOST comprehensive and actionable intelligence?

Options

  • ARelying solely on VirusTotal for file hash lookups and URL reputation checks to block known
  • BSubmitting all suspicious email attachments to WildFire for immediate dynamic analysis and
  • CConfiguring email gateways to block all attachments with a '.exe' extension, regardless of their
  • DDeveloping custom YARA rules based on open-source intelligence on similar campaigns and
  • EImplementing strict egress filtering to prevent any outbound connections on non-standard ports,

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    73% (32)
  • C
    5% (2)
  • D
    14% (6)
  • E
    7% (3)

Explanation

This question demands a comprehensive and actionable defense against a sophisticated, evolving threat. Option B combines the strengths of WildFire for rapid, automated technical analysis of new malware variants (generating signatures for NGFWs) with the strategic and tactical intelligence from Unit 42. Unit 42's reports often cover nation-state TTPs, campaign attribution, motivation, and broader context, which is crucial for understanding the adversary beyond just individual malware samples. This combination allows for both automated, real-time protection (WildFire) and informed, proactive defense planning based on deep threat actor knowledge (Unit 42).

Topics

#WildFire#Unit 42#spear-phishing defense#threat intelligence

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice