200-201 exam dumps

200-201 practice question 26 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 26

Single answer

During an investigation of a suspicious file, a cybersecurity analyst performs static analysis and discovers that the file contains obfuscated code and multiple references to known malicious domains. What should the analyst prioritize as the next step in the malware analysis process?

  1. A

    Execute the file in a secure sandbox environment to observe its behavior.

  2. B

    Immediately delete the file to prevent potential execution.

  3. C

    Search for the file hash in threat intelligence databases.

  4. D

    Decrypt the obfuscated code manually to understand its functionality.

Show answer and explanation

Correct answer: A

Explanation

The next step in malware analysis after detecting obfuscated code and malicious domain references is to perform dynamic analysis by executing the file in a secure sandbox environment. This allows the analyst to observe its behavior, including any network communications or system modifications, while minimizing risk to the production environment. Static methods like searching for hashes and decrypting code are valuable, but dynamic analysis is often prioritized for actionable insights.

  • A. Correct.

    Executing the file in a secure sandbox environment allows the analyst to observe its real-time behavior and identify its potential impact, which is a key step in dynamic malware analysis.

  • B. Incorrect.

    Deleting the file without further analysis prevents the analyst from gathering critical information about the malware's behavior, indicators of compromise (IOCs), and potential mitigation strategies.

  • C. Incorrect.

    Searching for the file hash in threat intelligence databases can provide useful context, but it does not directly help in understanding the behavior of obfuscated code or confirming its malicious intent.

  • D. Incorrect.

    Decrypting obfuscated code manually can be highly time-consuming and is typically not the immediate next step, especially if dynamic analysis in a sandbox can provide faster insights.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam