300-215 exam dumps

300-215 practice question 66 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 66

Select 3

During an investigation of a suspected fileless malware attack, you are using Cisco Secure Endpoint integrated with MITRE ATT&CK techniques. Which approaches would help you analyze the fileless malware effectively?

  1. A

    Examining memory dumps for suspicious PowerShell commands

  2. B

    Analyzing network traffic for anomalous communications

  3. C

    Scanning the filesystem for malicious executable files

  4. D

    Reviewing Windows Event Logs for script-based attacks

  5. E

    Using static analysis tools to inspect binary files

Show answer and explanation

Correct answers: A, B, D

Explanation

Fileless malware operates without leaving traditional file-based artifacts on the disk, often residing in memory or leveraging legitimate tools like PowerShell or WMI. Effective analysis techniques include examining memory dumps, analyzing network traffic for anomalies, and reviewing logs for suspicious script execution. Traditional file-based analysis methods, such as scanning for executables or using static analysis tools, are typically ineffective against fileless malware.

  • A. Correct.

    Examining memory dumps is critical for detecting fileless malware, as it often resides in memory and utilizes tools like PowerShell.

  • B. Correct.

    Analyzing network traffic can reveal suspicious connections or data exfiltration attempts made by the malware.

  • C. Incorrect.

    Fileless malware does not typically involve malicious executable files stored on disk, making this approach less effective.

  • D. Correct.

    Windows Event Logs can expose malicious script execution or other indicators of fileless malware activity.

  • E. Incorrect.

    Static analysis tools are designed for inspecting binaries or files, which are not relevant to fileless malware as it operates without traditional file artifacts.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam