300-215 Question 220
Select 3You are performing a forensic analysis on an endpoint that has exhibited suspicious behavior. Initial antivirus scans did not detect any malware, and you suspect a sophisticated threat may be present. Which next steps should you take to further evaluate the files on the endpoint and perform an ad-hoc scan using Cisco Secure Endpoint?
- A
Use Cisco Secure Endpoint to perform a file trajectory analysis for suspicious files.
- B
Submit suspicious files to Cisco Threat Grid for advanced malware analysis.
- C
Quarantine the entire endpoint to prevent any further malicious activity.
- D
Run a retrospective analysis in Cisco Secure Endpoint to identify previously undetected threats.
- E
Reboot the endpoint to clear any potentially malicious processes from memory.
Show answer and explanation
Correct answers: A, B, D
Explanation
When evaluating files from endpoints and performing ad-hoc scans, leveraging Cisco Secure Endpoint's file trajectory and retrospective analysis tools allows for a deeper inspection of suspicious files. Submitting files to Cisco Threat Grid provides advanced analysis to uncover sophisticated threats. These steps ensure a thorough investigation while maintaining the integrity of the forensic process.
- A. Correct.
File trajectory analysis in Cisco Secure Endpoint helps track the lifecycle of a file across the environment and can reveal suspicious activity, making it a critical step in deeper evaluation.
- B. Correct.
Cisco Threat Grid provides advanced malware analysis, including detonating files in a sandbox environment, which is essential for identifying sophisticated threats.
- C. Incorrect.
Quarantining the entire endpoint is not a standard step for initial forensic evaluation; it could disrupt the investigation process unless the threat is confirmed to be highly destructive.
- D. Correct.
Retrospective analysis in Cisco Secure Endpoint allows you to identify threats that may have been missed during initial scans, making it a key step in uncovering hidden or previously undetected malware.
- E. Incorrect.
Rebooting the endpoint may disrupt forensic artifacts and is not recommended during an ongoing forensic investigation.