300-215 Question 223
Select 3During an incident investigation, you suspect that a malicious file resides on several endpoints within your organization. You have access to Cisco Secure Endpoint. What would be the recommended next steps to evaluate these files and perform ad-hoc scans on the endpoints?
- A
Use Cisco Secure Endpoint's Device Trajectory feature to trace the file's activity across endpoints.
- B
Quarantine all endpoints in the network immediately to prevent further spread of the file.
- C
Manually collect suspect files from endpoints and analyze them using external tools.
- D
Initiate a targeted scan for the suspect file using Cisco Secure Endpoint's Orbital Advanced Search.
- E
Submit the suspect file to Cisco Threat Grid for dynamic analysis.
Show answer and explanation
Correct answers: A, D, E
Explanation
To evaluate a suspicious file and perform ad-hoc scans on endpoints effectively, it’s important to leverage Cisco Secure Endpoint's built-in features such as Device Trajectory to trace the file's activity, Orbital Advanced Search for targeted scans, and Cisco Threat Grid for dynamic analysis. These tools provide a comprehensive approach to forensic analysis, enabling rapid and informed decision-making while minimizing manual effort.
- A. Correct.
The Device Trajectory feature in Cisco Secure Endpoint allows you to trace the lifecycle of the file across endpoints, providing valuable insights into its behavior and propagation.
- B. Incorrect.
Quarantining all endpoints immediately is not a recommended action unless the situation is critical and confirmed. It can cause unnecessary disruption and could hinder investigation efforts.
- C. Incorrect.
Manually collecting files can be time-consuming and less efficient compared to using automated tools provided by Cisco Secure Endpoint, which are designed for such tasks.
- D. Correct.
Orbital Advanced Search enables you to perform targeted scans for specific files or indicators of compromise (IOCs) on endpoints, making it a crucial step in evaluating the file.
- E. Correct.
Submitting the file to Cisco Threat Grid allows for dynamic analysis, providing detailed insights into the file’s behavior and potential threats.