350-201 exam dumps

350-201 practice question 185 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 185

Select 3

During an investigation, your team identifies a suspicious binary file downloaded onto a compromised endpoint. You are tasked with performing reverse engineering to determine the file’s functionality and potential threats. Which of the following tools or techniques would be most appropriate to analyze the binary and understand its behavior?

  1. A

    Static analysis using a disassembler like IDA Pro or Ghidra

  2. B

    Dynamic analysis in a controlled sandbox environment

  3. C

    Packet capture analysis using Wireshark

  4. D

    Performing a vulnerability scan using Cisco Secure Scanner

  5. E

    Checking the file hash against a threat intelligence database

Show answer and explanation

Correct answers: A, B, E

Explanation

Reverse engineering involves both static and dynamic analysis to fully understand the structure and behavior of a binary file. Tools like IDA Pro or Ghidra help analyze the code without execution, while sandbox environments enable observation of runtime behavior. Additionally, checking the file hash against threat intelligence databases can provide context about the file's origin or malicious intent. While packet capture and vulnerability scanning are useful in broader cybersecurity contexts, they are not specific to reverse engineering tasks.

  • A. Correct.

    Static analysis using a disassembler like IDA Pro or Ghidra is a core reverse engineering technique that allows you to analyze the binary code structure and understand its logic without executing it.

  • B. Correct.

    Dynamic analysis involves executing the binary in a controlled sandbox environment to observe its runtime behavior, such as network communication or system changes, which is essential for reverse engineering.

  • C. Incorrect.

    Packet capture analysis using Wireshark is useful for monitoring network traffic but does not directly assist in reverse engineering the binary itself.

  • D. Incorrect.

    Performing a vulnerability scan using Cisco Secure Scanner is unrelated to reverse engineering and is instead used to identify known vulnerabilities in systems and applications.

  • E. Correct.

    Checking the file hash against a threat intelligence database can help identify if the file is known malware or associated with previous attacks, which is a valuable step in the reverse engineering process.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam