300-215 Question 65
Single answerA security analyst is conducting a forensic investigation using Cisco Secure Endpoint. During the investigation, they need to determine which processes on an affected endpoint were running prior to malware execution. Which forensic technique is most appropriate for the analyst to use in this situation?
- A
Analyze the Endpoint Isolation logs in Cisco Secure Endpoint
- B
Review the Process Explorer feature in Cisco Secure Endpoint
- C
Perform a retrospective analysis using Cisco Secure Network Analytics
- D
Leverage the File Trajectory feature in Cisco Secure Endpoint
Show answer and explanation
Correct answer: B
Explanation
To determine which processes were running prior to malware execution, the analyst should use the Process Explorer feature in Cisco Secure Endpoint. This forensic tool provides detailed visibility into the lifecycle of processes on the endpoint, allowing the analyst to trace the activity leading up to the compromise. Other tools like Endpoint Isolation, File Trajectory, or Network Analytics have valuable purposes but are not suitable for analyzing process-level details.
- A. Incorrect.
Endpoint Isolation logs are used to isolate the endpoint from the network to prevent further damage, but they do not provide detailed insights into the processes running prior to malware execution.
- B. Correct.
The Process Explorer feature in Cisco Secure Endpoint allows the analyst to review detailed information about processes running on the endpoint, including historical process activity, making it the most appropriate choice for this scenario.
- C. Incorrect.
Cisco Secure Network Analytics is used to monitor and analyze network traffic for anomalies, but it is not designed to provide insights into endpoint processes specifically.
- D. Incorrect.
The File Trajectory feature in Cisco Secure Endpoint is used to track the movement and interaction of files on the endpoint, but it does not provide details about the processes running on the endpoint.