300-215 Question 82
Single answerA security analyst is investigating a potential malware infection on a host within the network. The analyst uses Cisco Secure Endpoint (formerly AMP for Endpoints) to analyze the processes running on the host. During the investigation, they notice a process with an unusual name consuming high CPU and memory resources, which is not associated with any legitimate application installed on the system. Which course of action should the analyst take to further investigate and confirm the process as malicious?
- A
Use Cisco Secure Endpoint to retrieve the process hash and check its reputation in Cisco Threat Grid.
- B
Immediately terminate the process using Cisco Secure Endpoint.
- C
Quarantine the host using Cisco ISE to isolate it from the network.
- D
Analyze the process behavior using Cisco Stealthwatch for network-based anomalies.
Show answer and explanation
Correct answer: A
Explanation
The correct course of action during a process analysis is to gather evidence and confirm whether the process is malicious before taking further steps. Retrieving the process hash and checking its reputation in Cisco Threat Grid provides valuable threat intelligence to confirm its malicious nature. This ensures that the analyst has sufficient evidence to take appropriate remediation actions, such as terminating the process or isolating the host.
- A. Correct.
Retrieving the process hash and checking its reputation in Cisco Threat Grid allows the analyst to determine if the process is associated with known malware, providing evidence before taking any action.
- B. Incorrect.
Terminating the process immediately may disrupt a critical investigation and could result in the loss of forensic evidence. This action should only be taken after confirming the process is malicious.
- C. Incorrect.
Quarantining the host is a precautionary action that can be taken after confirming malicious activity. However, it is not the first step in a process analysis investigation.
- D. Incorrect.
Cisco Stealthwatch is used for network traffic analysis and is not directly relevant to analyzing host-based processes. It would not provide insights into the behavior of a specific process running on an endpoint.