300-215 Question 222
Select 3You are a cybersecurity analyst investigating a potential malware infection on an endpoint. Using Cisco Secure Endpoint, you have identified a suspicious file on the endpoint. What should be your next steps to evaluate the file and determine its risk level?
- A
Upload the file to Cisco Threat Grid for behavioral analysis.
- B
Configure a custom detection rule in Cisco Secure Endpoint to block the file globally on all endpoints.
- C
Perform a retrospective analysis in Cisco Secure Endpoint to check for its prevalence and history in the environment.
- D
Conduct an ad-hoc scan on the endpoint to confirm if other malicious files or processes are present.
- E
Immediately quarantine the endpoint without further analysis.
Show answer and explanation
Correct answers: A, C, D
Explanation
When evaluating a suspicious file, it is essential to gather sufficient evidence before making impactful decisions. Uploading the file to Cisco Threat Grid allows for a detailed behavioral analysis, while retrospective analysis in Cisco Secure Endpoint provides context on the file's history and prevalence. Performing an ad-hoc scan on the endpoint helps identify potential related artifacts. These steps collectively provide a comprehensive understanding of the file's risk level before implementing containment measures like quarantining or blocking the file globally.
- A. Correct.
Uploading the file to Cisco Threat Grid allows you to perform a behavioral analysis, providing detailed information about the file’s actions and potential malicious indicators.
- B. Incorrect.
Configuring a custom detection rule is a premature step at this stage, as it requires confirmation that the file is malicious, which is not yet established.
- C. Correct.
Performing a retrospective analysis helps determine if the file has been seen in the environment before and can provide context on its potential impact.
- D. Correct.
Conducting an ad-hoc scan helps identify if the endpoint has additional malicious artifacts or processes that may be related.
- E. Incorrect.
Immediately quarantining the endpoint is overly aggressive without confirming the nature of the threat and could disrupt legitimate business processes unnecessarily.