300-215 exam dumps

300-215 practice question 67 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 67

Select 4

A cybersecurity analyst is investigating suspicious activity on a Windows endpoint and suspects the presence of fileless malware. Using the MITRE ATT&CK framework, which methods should the analyst prioritize to effectively perform fileless malware analysis?

  1. A

    Analyze PowerShell scripts and commands executed on the system

  2. B

    Inspect scheduled tasks or cron jobs for unusual activity

  3. C

    Perform deep analysis of static malware files in the system's Downloads folder

  4. D

    Examine registry keys for persistence mechanisms

  5. E

    Monitor memory for malicious code injection or abnormal processes

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Fileless malware operates without traditional file artifacts, leveraging techniques such as in-memory execution, abuse of system utilities (e.g., PowerShell), and persistence mechanisms like registry modifications or scheduled tasks. Effective analysis requires focusing on these behaviors rather than searching for static files. By using the MITRE ATT&CK framework, analysts can identify and prioritize these techniques, enabling a more targeted and efficient response.

  • A. Correct.

    PowerShell scripts and commands are commonly exploited by fileless malware, as they run directly in memory without leaving traditional file traces.

  • B. Correct.

    Scheduled tasks or cron jobs can be used by attackers to execute malicious activities persistently without dropping files on disk.

  • C. Incorrect.

    Fileless malware does not rely on traditional static files stored in disk locations like the Downloads folder, making this method ineffective for this specific type of analysis.

  • D. Correct.

    Registry keys are a known persistence vector for fileless malware, as they can store malicious commands or scripts that execute during startup.

  • E. Correct.

    Monitoring memory is crucial because fileless malware often resides in memory rather than on disk, using techniques such as code injection or process hollowing.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam