350-201 exam dumps

350-201 practice question 180 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 180

Select 3

A security analyst is tasked with analyzing a suspicious file discovered on a corporate endpoint. The analyst decides to follow the malware analysis process to determine its behavior. Which of the following steps should the analyst include in their process?

  1. A

    Perform static analysis to examine the file without executing it.

  2. B

    Deploy the file to a live production environment to observe its impact.

  3. C

    Execute the file in a controlled sandbox environment for dynamic analysis.

  4. D

    Correlate the file's hash against threat intelligence databases.

  5. E

    Disable endpoint protection and execute the file to bypass security restrictions.

Show answer and explanation

Correct answers: A, C, D

Explanation

The malware analysis process generally involves both static and dynamic analysis to identify malicious behavior safely. Static analysis examines the file without execution, while dynamic analysis involves running it in a controlled sandbox environment. Additionally, correlating the file's hash with threat intelligence databases can provide valuable information about known threats. Risky actions, such as deploying malware in production environments or disabling endpoint protection, should always be avoided.

  • A. Correct.

    Performing static analysis is a critical step to examine the file's properties, such as headers, strings, and embedded resources, without running the file. This helps identify potential malicious intent early in the process.

  • B. Incorrect.

    Deploying the file to a live production environment is highly risky and not a recommended step in any malware analysis process, as it could compromise the environment.

  • C. Correct.

    Executing the file in a controlled sandbox environment is an essential dynamic analysis step to observe its behavior in a safe and isolated space.

  • D. Correct.

    Correlating the file's hash against threat intelligence databases helps identify if the file matches known malware signatures, expediting the identification process.

  • E. Incorrect.

    Disabling endpoint protection and executing the file is unsafe and counterproductive, as it could allow the malware to compromise the system or network.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam