300-215 exam dumps

300-215 practice question 81 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 81

Select 4

During a forensic investigation, a security analyst is tasked with analyzing suspicious processes running on a compromised endpoint. The analyst uses Cisco Secure Endpoint to examine process execution details and identifies an unknown process consuming significant system resources. What should the analyst prioritize to determine if the process is malicious?

  1. A

    Check the process's parent-child relationships to determine its origin.

  2. B

    Analyze the process's hash value and compare it against threat intelligence databases.

  3. C

    Terminate the process immediately to prevent further compromise.

  4. D

    Review the command-line arguments used to initiate the process.

  5. E

    Investigate the process's network connections for suspicious activity.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Analyzing processes during forensic investigations involves gathering comprehensive evidence to determine their legitimacy. Parent-child relationships, hash analysis, command-line arguments, and network connection reviews provide valuable context for identifying malicious activity. Simply terminating a process without proper analysis risks losing evidence or disrupting legitimate operations.

  • A. Correct.

    Checking the process's parent-child relationships helps determine if the process was initiated by a legitimate application or a malicious actor.

  • B. Correct.

    Analyzing the process's hash value against threat intelligence databases can help confirm if the process is associated with known malware.

  • C. Incorrect.

    Terminating the process without sufficient evidence may disrupt legitimate activity and lose critical forensic data.

  • D. Correct.

    Reviewing the command-line arguments provides context about how the process was initiated, which can reveal signs of malicious behavior.

  • E. Correct.

    Investigating the process's network connections can help identify communication with malicious IP addresses or domains.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam