300-215 exam dumps

300-215 practice question 82 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 82

Single answer

A security analyst is investigating a potential malware infection on a host within the network. The analyst uses Cisco Secure Endpoint (formerly AMP for Endpoints) to analyze the processes running on the host. During the investigation, they notice a process with an unusual name consuming high CPU and memory resources, which is not associated with any legitimate application installed on the system. Which course of action should the analyst take to further investigate and confirm the process as malicious?

  1. A

    Use Cisco Secure Endpoint to retrieve the process hash and check its reputation in Cisco Threat Grid.

  2. B

    Immediately terminate the process using Cisco Secure Endpoint.

  3. C

    Quarantine the host using Cisco ISE to isolate it from the network.

  4. D

    Analyze the process behavior using Cisco Stealthwatch for network-based anomalies.

Show answer and explanation

Correct answer: A

Explanation

The correct course of action during a process analysis is to gather evidence and confirm whether the process is malicious before taking further steps. Retrieving the process hash and checking its reputation in Cisco Threat Grid provides valuable threat intelligence to confirm its malicious nature. This ensures that the analyst has sufficient evidence to take appropriate remediation actions, such as terminating the process or isolating the host.

  • A. Correct.

    Retrieving the process hash and checking its reputation in Cisco Threat Grid allows the analyst to determine if the process is associated with known malware, providing evidence before taking any action.

  • B. Incorrect.

    Terminating the process immediately may disrupt a critical investigation and could result in the loss of forensic evidence. This action should only be taken after confirming the process is malicious.

  • C. Incorrect.

    Quarantining the host is a precautionary action that can be taken after confirming malicious activity. However, it is not the first step in a process analysis investigation.

  • D. Incorrect.

    Cisco Stealthwatch is used for network traffic analysis and is not directly relevant to analyzing host-based processes. It would not provide insights into the behavior of a specific process running on an endpoint.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam