300-215 Question 54
Single answerA security analyst is conducting a forensic investigation on a compromised endpoint using Cisco Secure Endpoint. The analyst suspects that malicious behavior is occurring but cannot find evidence within traditional disk-based logs. Which memory forensics tool integrated with Cisco technologies can the analyst use to capture and analyze live memory for further investigation?
- A
Cisco AMP for Endpoints Orbital Advanced Search
- B
Volatility Framework
- C
Cisco Threat Grid
- D
Cisco Umbrella Investigate
Show answer and explanation
Correct answer: B
Explanation
Memory forensics tools are essential for analyzing live memory to uncover malicious artifacts or hidden processes that may not be visible in traditional disk-based logs. The Volatility Framework is a widely used open-source tool for memory analysis and can be paired with other Cisco tools for comprehensive forensic investigations. While other Cisco technologies assist with threat intelligence, endpoint queries, or malware analysis, they do not provide direct memory forensics capabilities.
- A. Incorrect.
Cisco AMP for Endpoints Orbital Advanced Search is a powerful tool for querying endpoint data, but it is not designed for live memory analysis or memory forensics.
- B. Correct.
Volatility Framework is an open-source memory forensics tool that can be integrated into forensic workflows and is capable of analyzing live memory dumps for malicious activities. It is commonly used for this purpose.
- C. Incorrect.
Cisco Threat Grid focuses on sandboxing and malware analysis, not on live memory forensics.
- D. Incorrect.
Cisco Umbrella Investigate provides DNS and domain-level threat intelligence but does not have memory forensics capabilities.