300-215 exam dumps

300-215 practice question 68 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 68

Select 4

A security analyst is investigating a system suspected of being infected with fileless malware. Using Cisco Secure Endpoint and referencing the MITRE ATT&CK framework, which of the following methods should they prioritize to analyze and detect fileless malware behavior?

  1. A

    Monitor process injection activities into legitimate processes

  2. B

    Analyze registry modifications and script execution patterns

  3. C

    Inspect executable files stored in the system's temporary folders

  4. D

    Correlate PowerShell command usage with process execution data

  5. E

    Perform static analysis on all downloaded files

  6. F

    Track interactions with remote command-and-control (C2) servers

Show answer and explanation

Correct answers: A, B, D, F

Explanation

Fileless malware is designed to evade traditional signature-based detection methods by operating directly in memory or leveraging legitimate system tools. According to the MITRE ATT&CK framework, techniques such as monitoring process injection, analyzing registry modifications, correlating PowerShell usage, and tracking C2 server interactions are effective in identifying fileless malware behavior. These methods align with Cisco Secure Endpoint’s capabilities for dynamic and behavior-based analysis.

  • A. Correct.

    Fileless malware often leverages process injection techniques to evade detection by running malicious code within legitimate processes.

  • B. Correct.

    Registry modifications and script execution patterns are common indicators of fileless malware, as it frequently uses these methods to persist or execute.

  • C. Incorrect.

    Inspecting executable files in temporary folders is not a primary method for detecting fileless malware, as it typically resides in memory or uses native tools instead of traditional files.

  • D. Correct.

    PowerShell is commonly used by fileless malware for execution. Correlating its usage with processes can reveal malicious activity.

  • E. Incorrect.

    Static analysis on downloaded files is less effective for fileless malware because it doesn't rely on traditional file-based methods.

  • F. Correct.

    Fileless malware often establishes communication with remote command-and-control (C2) servers, making this a critical aspect to monitor.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam