350-201 exam dumps

350-201 practice question 154 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 154

Select 3

You are investigating an incident where a suspected malicious file was downloaded from a website. A packet capture (PCAP) file from the time of the incident is available. Which artifacts or streams should you analyze within the PCAP file to confirm whether a malicious executable was downloaded?

  1. A

    The HTTP request headers to determine if the file download was initiated by a user or automated process.

  2. B

    The HTTP response body to extract and analyze the file content.

  3. C

    The DNS query and response streams to identify the domain associated with the file download.

  4. D

    The TLS handshake packets to verify the encryption type used during the file transfer.

  5. E

    The TCP stream for anomalies in session behavior, such as irregular packet retransmissions or resets.

Show answer and explanation

Correct answers: B, C, E

Explanation

To confirm whether a malicious executable was downloaded, you need to analyze artifacts that provide direct evidence of the file itself (e.g., HTTP response body), its origin (e.g., DNS streams), and anomalies in the transfer process (e.g., TCP stream). These artifacts help you reconstruct the incident and identify malicious activity effectively.

  • A. Incorrect.

    While HTTP request headers can provide context about how the file download was initiated, they do not directly confirm whether a malicious executable was downloaded.

  • B. Correct.

    The HTTP response body often contains the actual file content. Extracting and analyzing this content allows you to determine if a malicious executable was downloaded.

  • C. Correct.

    DNS query and response streams can reveal the domain associated with the file download, which can be cross-referenced with threat intelligence to identify malicious activity.

  • D. Incorrect.

    TLS handshake packets provide encryption details, but they do not help directly in identifying the content of the file or confirming if it is malicious.

  • E. Correct.

    The TCP stream can uncover anomalies in the session, such as irregular retransmissions or resets, which might indicate evasion techniques or issues during the transfer of malicious content.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam