SECOPS-PRO · Question #75
An incident response team is investigating a potential breach involving an internal server communicating with a suspicious external IP address. Initial checks on VirusTotal for the external IP yield n
The correct answer is A. WildFire's ability to perform deep, proprietary behavioral analysis of submitted malware samples, B. Unit 42's comprehensive, human-curated threat intelligence reports providing detailed adversary D. WildFire's automatic generation and distribution of new threat signatures to Palo Alto Networks. This scenario requires a combination of technical analysis, strategic intelligence, and proactive A (WildFire's deep behavioral analysis): This is crucial because VirusTotal yielded no results, indicating a potentially unknown or highly evasive C2. WildFire's ability to detonate
Question
An incident response team is investigating a potential breach involving an internal server communicating with a suspicious external IP address. Initial checks on VirusTotal for the external IP yield no results. Upon further investigation, network telemetry suggests the communication pattern is highly unusual and indicative of command-and-control (C2) activity. The team needs to determine if this C2 traffic is associated with a known threat actor, understand their TTPs, and identify specific exploit methods. Which of the following distinct characteristics, when comparing WildFire, Unit 42, and VirusTotal, are most critical for the team to leverage in this situation? (Select all that apply)
Options
- AWildFire's ability to perform deep, proprietary behavioral analysis of submitted malware samples,
- BUnit 42's comprehensive, human-curated threat intelligence reports providing detailed adversary
- CVirusTotal's aggregated community intelligence, allowing for rapid lookup of known bad hashes
- DWildFire's automatic generation and distribution of new threat signatures to Palo Alto Networks
- EThe ability of VirusTotal to conduct real-time deep packet inspection on live network traffic to
How the community answered
(57 responses)- A84% (48)
- C5% (3)
- E11% (6)
Explanation
This scenario requires a combination of technical analysis, strategic intelligence, and proactive A (WildFire's deep behavioral analysis): This is crucial because VirusTotal yielded no results, indicating a potentially unknown or highly evasive C2. WildFire's ability to detonate and analyze malware's C2 communication patterns, even to previously unlisted IPs, provides critical technical indicators. B (Unit 42's comprehensive threat intelligence): To understand if the C2 is linked to a known threat actor, their TTPs, and exploit methods, Unit 42's in-depth, human-curated reports are indispensable. They provide the strategic context that raw technical indicators often lack. D (WildFire's automatic signature generation and distribution): Once WildFire identifies novel malware and its C2, it automatically generates signatures that are pushed to, NGFWs, ensuring immediate and proactive network protection against the identified C2 traffic. C (VirusTotal's aggregated community intelligence): While useful for initial checks and known threats, it falls short when dealing with unknown or evasive C2 activity that has no public reputation yet. E (VirusTotal's ability to conduct real-time deep packet inspection): VirusTotal is a file/URL analysis service and does not perform real-time deep packet inspection on live network traffic. That's a function of network security devices or dedicated network forensic tools.
Topics
Community Discussion
No community discussion yet for this question.