Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 10 Question 66 Discussion

An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?
A) Upload the file signature to threat intelligence tools to determine if the file is malicious.
B) Monitor processes as this a standard behavior of Word macro embedded documents.
C) Contain the threat for further analysis as this is an indication of suspicious activity.
D) Investigate the sender of the email and communicate with the employee to determine the motives.

Cisco 300-215 Exam - Topic 10 Question 66 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 66
Topic #: 10
[All 300-215 Questions]

An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Willard
9 months ago
D seems too slow, we need to act fast!
upvoted 0 times
...
Deeanna
10 months ago
A is a good first step, always check the file signature.
upvoted 0 times
...
Pamella
10 months ago
Surprised this even made it to the engineer, sounds like a false alarm!
upvoted 0 times
...
Shawnta
10 months ago
I think B is more appropriate, could just be a macro.
upvoted 0 times
...
Bettina
10 months ago
Definitely C, suspicious activity needs to be contained.
upvoted 0 times
...
Hyun
10 months ago
I think investigating the sender could help, but if there's suspicious activity, shouldn't we contain it first?
upvoted 0 times
...
Mose
11 months ago
I’m a bit uncertain about whether monitoring processes is enough. I feel like we should take more immediate action.
upvoted 0 times
...
Cherry
11 months ago
This situation feels similar to a practice question we did on email threats. I think containing the threat might be the safest option.
upvoted 0 times
...
Lai
11 months ago
I remember something about PowerShell being used in attacks, but I'm not sure if it's always a sign of compromise.
upvoted 0 times
...
Sheridan
11 months ago
This is a tough one. I'm not sure if I'd go straight to containment, though. Might be worth investigating the sender and talking to the employee first to get a better understanding of what happened. That could help guide the next steps.
upvoted 0 times
...
Derick
11 months ago
Okay, I think I've got this. The fact that PowerShell was spawned by cmd.exe with a Word process as the grandparent is definitely suspicious. I'd recommend containing the threat and analyzing it further to see what's going on.
upvoted 0 times
...
Arlyne
11 months ago
Hmm, I'm a bit confused. The question mentions that there are no clear signs of compromise, so I'm not sure if that's the best approach. Maybe monitoring the processes would be a safer bet?
upvoted 0 times
...
Denny
11 months ago
This one seems tricky, but I think the key is to look for any signs of malicious activity. Uploading the file signature to threat intelligence tools could help identify if it's known malware.
upvoted 0 times
...
Emerson
11 months ago
I've seen questions like this before, and the key is to identify the method that doesn't fit with the others. I'm leaning towards varying cues in the natural environment as the exception, but I'll double-check my reasoning.
upvoted 0 times
...
Vashti
11 months ago
I'm torn between B and D. B seems plausible since managers depend on custom fields, but I feel like D might relate more directly to the Managers role.
upvoted 0 times
...
Annabelle
11 months ago
This looks like a tricky question on Trails. I'll need to think carefully about the differences between the various Trails components.
upvoted 0 times
...
Kristin
11 months ago
I remember learning about surface plates in class. They're used for referencing measurements, establishing datums, and keeping delicate parts safe. I'll mark the options that cover those uses.
upvoted 0 times
...
Buck
1 year ago
Ah, the age-old question: 'To open or not to open?' I say, better safe than sorry. Contain that threat, my friend!
upvoted 0 times
Linwood
1 year ago
B) Monitor processes as this a standard behavior of Word macro embedded documents.
upvoted 0 times
...
Chu
1 year ago
C) Contain the threat for further analysis as this is an indication of suspicious activity.
upvoted 0 times
...
Geraldine
1 year ago
A) Upload the file signature to threat intelligence tools to determine if the file is malicious.
upvoted 0 times
...
...
Tequila
1 year ago
Ooh, an empty Word doc spawning PowerShell? Sounds like a classic case of 'Looks can be deceiving.' Gotta go with option C on this one.
upvoted 0 times
...
Earleen
1 year ago
Threat intelligence, huh? I bet the file has some juicy malware that'll make the hackers laugh all the way to the bank. Better contain this before it spreads!
upvoted 0 times
Gwenn
1 year ago
B) Monitor processes as this a standard behavior of Word macro embedded documents.
upvoted 0 times
...
Refugia
1 year ago
C) Contain the threat for further analysis as this is an indication of suspicious activity.
upvoted 0 times
...
Hannah
1 year ago
A) Upload the file signature to threat intelligence tools to determine if the file is malicious.
upvoted 0 times
...
...
Rashida
1 year ago
Hmm, standard behavior of Word macros? I think not. Something fishy is going on here. Better investigate further!
upvoted 0 times
...
Ashleigh
1 year ago
C'mon, if PowerShell is involved, it's gotta be bad news! Contain that threat, my friend!
upvoted 0 times
Tamar
1 year ago
C) Contain the threat for further analysis as this is an indication of suspicious activity.
upvoted 0 times
...
Jill
1 year ago
A) Upload the file signature to threat intelligence tools to determine if the file is malicious.
upvoted 0 times
...
Luis
1 year ago
C) Contain the threat for further analysis as this is an indication of suspicious activity.
upvoted 0 times
...
Leonie
1 year ago
A) Upload the file signature to threat intelligence tools to determine if the file is malicious.
upvoted 0 times
...
...
Alonzo
1 year ago
I believe containing the threat for further analysis is also a good idea. We need to be cautious.
upvoted 0 times
...
Kiley
1 year ago
I agree with Andra. It's important to determine if the file is malicious.
upvoted 0 times
...
Andra
1 year ago
I think the engineer should upload the file signature to threat intelligence tools.
upvoted 0 times
...

Save Cancel