350-201 exam dumps

350-201 practice question 193 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 193

Select 3

You are a cybersecurity analyst investigating a suspicious file flagged by the Endpoint Detection and Response (EDR) system. Dynamic analysis was performed, but it did not reveal any malicious behavior. The file appears encrypted or heavily obfuscated, and there is no clear indication of its purpose. Which of the following would justify the need for additional static malware analysis?

  1. A

    The file contains suspicious strings or encoded data that may indicate malicious functionality.

  2. B

    The file exhibits polymorphic behavior, altering its code structure upon execution.

  3. C

    The file's hash matches a known malware sample in threat intelligence databases.

  4. D

    The file lacks dynamic activity but includes uncommon API calls or code patterns.

  5. E

    The file is signed with a valid and trusted digital certificate.

Show answer and explanation

Correct answers: A, B, D

Explanation

Static malware analysis is crucial when suspicious or obfuscated code cannot be fully understood through dynamic analysis alone. Indicators such as encoded data, polymorphic behavior, or unusual code patterns justify further investigation, as they may signal hidden malicious functionality. However, certain factors like trusted certificates or known hashes may not necessitate static analysis.

  • A. Correct.

    Suspicious strings or encoded data within the file could point to malicious intent, requiring static analysis to decode and understand its behavior.

  • B. Correct.

    Polymorphic behavior makes dynamic analysis less reliable, as the malware can change its structure. Static analysis is needed to evaluate the underlying code.

  • C. Incorrect.

    If the file's hash matches a known malware sample, static analysis may not be necessary as its behavior is already documented.

  • D. Correct.

    Uncommon API calls or code patterns suggest the presence of potentially malicious functionality that might not manifest during dynamic analysis, making static analysis essential.

  • E. Incorrect.

    A valid and trusted digital certificate does not inherently indicate malicious behavior, so additional static analysis would not be warranted in this case.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam