nerdexam
CompTIA

SY0-701 · Question #733

A security analyst receives an alert that there was an attempt to download known malware. Which of the following actions would allow the best chance to analyze the malware?

The correct answer is D. Obtain and execute the malware in a sandbox environment and perform packet captures.. To analyze malware behavior in detail, the best approach is to execute the malware in a sandbox and capture its network activity. This provides real-time analysis of how the malware behaves, spreads, and communicates.

Submitted by ahmad_uae· Mar 6, 2026Security Operations

Question

A security analyst receives an alert that there was an attempt to download known malware. Which of the following actions would allow the best chance to analyze the malware?

Options

  • AReview the IPS logs and determine which command-and-control IPs were blocked.
  • BAnalyze application logs to see how the malware attempted to maintain persistence.
  • CRun vulnerability scans to check for systems and applications that are vulnerable to the malware.
  • DObtain and execute the malware in a sandbox environment and perform packet captures.

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    19% (9)
  • C
    10% (5)
  • D
    67% (32)

Explanation

To analyze malware behavior in detail, the best approach is to execute the malware in a sandbox and capture its network activity. This provides real-time analysis of how the malware behaves, spreads, and communicates.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice