350-201 Question 174
Select 3A security analyst at your organization identifies suspicious activity involving an employee's endpoint, which appears to be part of a potential malware infection. What steps should the analyst take to properly investigate this case?
- A
Isolate the affected endpoint from the network to prevent further spread.
- B
Immediately delete all suspicious files from the endpoint to eliminate the threat.
- C
Analyze endpoint logs and network traffic for indicators of compromise (IOCs).
- D
Perform a full antivirus scan and document all findings.
- E
Schedule a routine maintenance check for the endpoint after a week.
Show answer and explanation
Correct answers: A, C, D
Explanation
Investigating cases of potential malware infection requires a systematic approach. Isolating the endpoint prevents further spread, while analyzing logs and traffic helps identify the scope and source of the attack. A full antivirus scan aids in identifying the malware and collecting evidence for remediation and reporting. Immediate deletion of files or delaying the response could compromise evidence or allow the threat to propagate.
- A. Correct.
Isolating the affected endpoint is a critical first step to prevent the malware from spreading within the network while the investigation is conducted.
- B. Incorrect.
Deleting suspicious files immediately without proper analysis can eliminate critical evidence needed to understand the scope and source of the infection.
- C. Correct.
Analyzing logs and traffic for IOCs is essential for understanding how the malware operates and identifying other potentially affected systems.
- D. Correct.
Performing a full antivirus scan can help detect and document the specific malware present and assist in remediation efforts.
- E. Incorrect.
Delaying action by scheduling maintenance after a week is a poor response to a malware infection and could result in further propagation of the threat.