300-215 exam dumps

300-215 practice question 221 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 221

Select 3

During an investigation of potential malware on an endpoint, you have reviewed the logs and identified a suspicious file. Using Cisco Secure Endpoint, what should be the next step in evaluating this file and conducting an ad-hoc scan?

  1. A

    Hash the suspicious file and search for its reputation in the Cisco Secure Endpoint Threat Intelligence database.

  2. B

    Quarantine the suspicious file immediately without any further analysis to prevent potential spread.

  3. C

    Run a custom endpoint scan targeting the directory containing the suspicious file to detect other anomalies.

  4. D

    Upload the suspicious file to Cisco Threat Grid for dynamic analysis.

  5. E

    Ignore the file if no immediate malicious behavior is detected in the logs.

Show answer and explanation

Correct answers: A, C, D

Explanation

To evaluate a suspicious file effectively, you should first determine its reputation by hashing it and checking against threat intelligence databases. If the file is not immediately identifiable, conducting a custom endpoint scan and uploading the file to Cisco Threat Grid for dynamic analysis are critical next steps to gain insights into its behavior and identify potential threats. Quarantining or ignoring the file without further analysis could lead to premature conclusions or missed threats.

  • A. Correct.

    Hashing the file and searching for its reputation using Cisco Secure Endpoint Threat Intelligence is an important forensic step to determine if the file is known to be malicious or benign.

  • B. Incorrect.

    Quarantining the file immediately without further analysis may disrupt operations unnecessarily. This step should only be taken after confirming malicious behavior.

  • C. Correct.

    Running a custom endpoint scan will help identify other suspicious or related files in the same directory or across the endpoint, providing a more comprehensive view of potential threats.

  • D. Correct.

    Uploading the suspicious file to Cisco Threat Grid for dynamic analysis allows you to observe its behavior in a controlled environment and determine if it is malicious.

  • E. Incorrect.

    Ignoring the file without further investigation could allow malicious activity to go undetected, compromising the security of the system.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam