exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 35 discussion

Actual exam question from Cisco's 350-201
Question #: 35
Topic #: 1
[All 350-201 Questions]


Refer to the exhibit. An engineer is analyzing this Vlan0392-int12-239.pcap file in Wireshark after detecting a suspicious network activity. The origin header for the direct IP connections in the packets was initiated by a google chrome extension on a WebSocket protocol. The engineer checked message payloads to determine what information was being sent off-site but the payloads are obfuscated and unreadable. What does this STIX indicate?

  • A. The extension is not performing as intended because of restrictions since ports 80 and 443 should be accessible
  • B. The traffic is legitimate as the google chrome extension is reaching out to check for updates and fetches this information
  • C. There is a possible data leak because payloads should be encoded as UTF-8 text
  • D. There is a malware that is communicating via encrypted channels to the command and control server
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
marceus
2 months, 3 weeks ago
Selected Answer: D
ChatGPT: The suspicious WebSocket connection initiated by the Google Chrome extension combined with obfuscated payloads is indicative of malware trying to hide its communication with a command and control server. This suggests malicious activity rather than legitimate behavior.
upvoted 1 times
...
TrainingTeam
6 months, 2 weeks ago
Selected Answer: D
The STIX (Structured Threat Information eXpression) in the context of the exhibit indicates a scenario where a Google Chrome extension is initiating direct IP connections using the WebSocket protocol, and the payloads are obfuscated and unreadable. This behavior is suspicious and suggests that the extension could be a front for malware that is using encrypted channels to communicate with a command and control server. The use of WebSockets and the obfuscation of payloads are common tactics used by malware authors to evade detection and maintain persistent control over compromised systems. The fact that the payloads cannot be decoded or read as UTF-8 text further supports the likelihood of malicious activity, as legitimate extensions would not typically need to obfuscate their communications.
upvoted 1 times
...
DrVoIP
2 years, 2 months ago
Without more information, it is difficult to determine the exact meaning of the STIX. However, the fact that direct IP connections are being initiated by a Google Chrome extension using the WebSocket protocol and that the message payloads are obfuscated and unreadable could indicate a possible data exfiltration or command and control communication. The obfuscation of payloads is a common technique used by malware to avoid detection and evade analysis. Therefore, option D, "There is malware that is communicating via encrypted channels to the command and control server," is a plausible interpretation of the situation. However, further analysis would be required to confirm this. - ChatGPT
upvoted 1 times
...
TOLU1985
2 years, 7 months ago
Selected Answer: C
C is correct https://www.extrahop.com/company/blog/2019/investigating-fake-chrome-extension-postman-part-1/
upvoted 1 times
...
kyle942
2 years, 7 months ago
For WebSocket communications, UTF-8 must be used over the wire for textual data (most Internet protocols use UTF-8 nowadays). That is dictated by the WebSocket protocol specification: After a successful handshake, clients and servers transfer data back and forth in conceptual units referred to in this specification as "messages".
upvoted 1 times
...
jaciro11
2 years, 8 months ago
Selected Answer: C
1Normally the connection is only over 80 or 443. 2The encoded not looks like UTF-8 3This looking like malicious request, the port is different Answer would be C
upvoted 1 times
...
Websantos
3 years, 3 months ago
https://www.extrahop.com/company/blog/2019/investigating-fake-chrome-extension-postman-part-1/ I will the correct answer is C
upvoted 2 times
...
CiscoTester
3 years, 5 months ago
Go to your extension settings, these can have regular updates. Websocket protocol can use TLS so encrypted traffic is most not an IoC. The traffic from websocket is masked to avoid problems with devices that do not understand the protocol. Answer is: B
upvoted 2 times
...
Bobster02
3 years, 6 months ago
I agree, D is correct.
upvoted 2 times
...
kou
3 years, 8 months ago
I think D is the correct answer.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago