350-201 exam dumps

350-201 practice question 197 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 197

Select 4

You are a security analyst tasked with performing static malware analysis on a suspicious executable file discovered in the network. Which of the following steps would be part of static malware analysis?

  1. A

    Examining the file’s embedded strings for suspicious URLs or commands

  2. B

    Disassembling the binary to analyze the program's instructions

  3. C

    Executing the file in a sandbox environment to observe its behavior

  4. D

    Extracting metadata from the file, such as compiler information and timestamps

  5. E

    Analyzing network traffic generated by the malware during execution

  6. F

    Checking the file's hash against known malware databases

Show answer and explanation

Correct answers: A, B, D, F

Explanation

Static malware analysis involves examining a file without executing it. This includes techniques such as inspecting embedded strings, disassembling the binary, extracting metadata, and comparing file hashes with known malware databases. Dynamic analysis, on the other hand, involves running the malware to observe its behavior, which is not part of static analysis.

  • A. Correct.

    Examining the file’s embedded strings is a common static malware analysis technique to identify potentially malicious indicators like URLs or commands without executing the file.

  • B. Correct.

    Disassembling the binary allows analysts to study the program's instructions statically, which is a key part of malware analysis without running the file.

  • C. Incorrect.

    Executing the file in a sandbox environment is part of dynamic malware analysis, not static analysis, as it involves running the file.

  • D. Correct.

    Extracting metadata such as compiler information and timestamps is a static analysis approach, as it doesn’t involve running the file.

  • E. Incorrect.

    Analyzing network traffic is a dynamic analysis activity since it involves monitoring the malware's behavior during execution.

  • F. Correct.

    Checking the file's hash against known malware databases is a static analysis method used to identify known malicious files without executing them.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam