350-201 exam dumps

350-201 practice question 186 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 186

Single answer

While investigating a suspicious executable file found on a company server, you are tasked with performing reverse engineering to determine its behavior. Using Cisco Secure Malware Analytics (formerly Threat Grid), what is the most effective next step to identify if the executable is malicious and understand its actions?

  1. A

    Upload the executable to Cisco Secure Malware Analytics and analyze the dynamic behavior in a safe sandbox environment.

  2. B

    Directly execute the file on a production server to observe its behavior in a real-world environment.

  3. C

    Disassemble the code manually using a tool like Ghidra or IDA Pro to analyze its static behavior.

  4. D

    Quarantine the file and wait for the next scheduled Cisco Talos update for automatic threat detection.

Show answer and explanation

Correct answer: A

Explanation

The most effective and safe method to begin analyzing a suspicious executable is using Cisco Secure Malware Analytics to perform dynamic analysis in a sandbox environment. This allows the behavior of the file to be observed in isolation, reducing the risk to production systems while providing valuable insights into its actions. Other methods, while valid, are either unsafe or less efficient as an initial step.

  • A. Correct.

    Uploading the executable to Cisco Secure Malware Analytics allows safe dynamic analysis in a controlled sandbox environment, which can reveal the file's behavior without risking production systems.

  • B. Incorrect.

    Executing the file on a production server is highly risky as it could compromise the system and spread malicious activity across the network.

  • C. Incorrect.

    While manual disassembly using tools like Ghidra or IDA Pro is a valid reverse engineering method, it is time-consuming and may not be the most efficient first step, especially when automated dynamic analysis is available.

  • D. Incorrect.

    Quarantining the file and waiting for an update is a passive approach and does not provide immediate insights into the file's behavior or potential impact.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam