exam questions

Exam 300-215 All Questions

View all questions & answers for the 300-215 exam

Exam 300-215 topic 1 question 9 discussion

Actual exam question from Cisco's 300-215
Question #: 9
Topic #: 1
[All 300-215 Questions]

A security team receives reports of multiple files causing suspicious activity on users' workstations. The file attempted to access highly confidential information in a centralized file server. Which two actions should be taken by a security analyst to evaluate the file in a sandbox? (Choose two.)

  • A. Inspect registry entries
  • B. Inspect processes.
  • C. Inspect file hash.
  • D. Inspect file type.
  • E. Inspect PE header.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️
Reference:
https://medium.com/@Flying_glasses/top-5-ways-to-detect-malicious-file-manually-d02744f7c43a

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CCNPWILL
9 months, 3 weeks ago
ChatGPT thinks: To evaluate the file in a sandbox, a security analyst should take the following actions: A. Inspect registry entries – This helps in identifying changes or additions to the system registry that could indicate malicious behavior or persistence mechanisms used by the file. B. Inspect processes – This involves checking for any processes that the file creates or interacts with, which can reveal suspicious activity or abnormal behavior associated with the file. Additionally, while not specifically requested, inspecting the file hash and PE header (if applicable) can provide further insight into the file's characteristics and origins
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...